Severity
5.7MEDIUM
EPSS
3.6%
top 12.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 13

Description

.NET Core and Visual Studio Information Disclosure Vulnerability

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.1 | Impact: 3.6

Affected Packages8 packages

Patches

🔴Vulnerability Details

3
CVEList
.NET Core and Visual Studio Information Disclosure Vulnerability2021-10-13
GHSA
Credential Disclosure in System.DirectoryServices.Protocols2021-10-12
OSV
Credential Disclosure in System.DirectoryServices.Protocols2021-10-12

📋Vendor Advisories

2
Red Hat
dotnet: System.DirectoryServices.Protocols.LdapConnection sends credentials in plaintext if TLS handshake fails2021-10-12
Microsoft
.NET Core and Visual Studio Information Disclosure Vulnerability2021-10-12
CVE-2021-41355 (MEDIUM CVSS 5.7) | .NET Core and Visual Studio Informa | cvebase.io