CVE-2022-34716
published 2022-08-09CVE-2022-34716: dotnet: External Entity Injection during XML signature verification .NET Spoofing Vulnerability An information disclosure vulnerability exists in .NET Core and…
medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.96%
78.2th percentile
dotnet: External Entity Injection during XML signature verification
.NET Spoofing Vulnerability
An information disclosure vulnerability exists in .NET Core and .NET. This issue can lead to unauthorized access to privileged information.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 3.1.0 < 3.1.28 | 3.1.28 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 6.0.0 < 6.0.8 | 6.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 3.1.0 < 3.1.28 | 3.1.28 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 6.0.0 < 6.0.8 | 6.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm | >= 3.1.0 < 3.1.28 | 3.1.28 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm | >= 6.0.0 < 6.0.8 | 6.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 3.1.0 < 3.1.28 | 3.1.28 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 6.0.0 < 6.0.8 | 6.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 3.1.0 < 3.1.28 | 3.1.28 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 6.0.0 < 6.0.8 | 6.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 3.1.0 < 3.1.28 | 3.1.28 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 6.0.0 < 6.0.8 | 6.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-arm64 | >= 6.0.0 < 6.0.8 | 6.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-x64 | >= 3.1.0 < 3.1.28 | 3.1.28 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-x64 | >= 6.0.0 < 6.0.8 | 6.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.win-arm | >= 3.1.0 < 3.1.28 | 3.1.28 |
| microsoft | microsoft.aspnetcore.app.runtime.win-arm | >= 6.0.0 < 6.0.8 | 6.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.win-arm64 | >= 3.1.0 < 3.1.28 | 3.1.28 |
| microsoft | microsoft.aspnetcore.app.runtime.win-arm64 | >= 6.0.0 < 6.0.8 | 6.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.win-x64 | >= 3.1.0 < 3.1.28 | 3.1.28 |
| microsoft | microsoft.aspnetcore.app.runtime.win-x64 | >= 6.0.0 < 6.0.8 | 6.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.win-x86 | >= 3.1.0 < 3.1.28 | 3.1.28 |
| microsoft | microsoft.aspnetcore.app.runtime.win-x86 | >= 6.0.0 < 6.0.8 | 6.0.8 |
| msrc | microsoft_visual_studio_2017_version_15.9 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.11 | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_msrc5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
dotnet: External Entity Injection during XML signature verification
vendor_redhat·2022-08-09·CVSS 5.9
CVE-2022-34716 [MEDIUM] CWE-611 dotnet: External Entity Injection during XML signature verification
dotnet: External Entity Injection during XML signature verification
.NET Spoofing Vulnerability
An information disclosure vulnerability exists in .NET Core and .NET. This issue can lead to unauthorized access to privileged information.
Microsoft
.NET Spoofing Vulnerability
vendor_msrc·2022-08-09·CVSS 5.9
CVE-2022-34716 [MEDIUM] .NET Spoofing Vulnerability
.NET Spoofing Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to successfully execute a blind XXE attack.
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to major loss of confidentiality (C:H) but have no effect on integrity (I:N) or on availability (A:N). What does that mean for this vulnerability?
Confidentiality is High, if an attacker successfuly exploits this it is information disclosure. While the attacker could read files that shouldn't be exposed, they wouldn't have the ability to modify them in any way (Integrity) or delete them to stop the app or server from functioning (Availability).
OSV
.NET Information Disclosure Vulnerability
osv·2024-02-03
CVE-2022-34716 [MEDIUM] .NET Information Disclosure Vulnerability
.NET Information Disclosure Vulnerability
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET Core 3.1 and .NET 6.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
An information disclosure vulnerability exists in .NET Core 3.1 and .NET 6.0 that could lead to unauthorized access of privileged information.
## Affected software
* Any .NET 6.0 application running on .NET 6.0.7 or earlier.
* Any .NET Core 3.1 applicaiton running on .NET Core 3.1.27 or earlier.
If your application uses the following package versions, ensure you update to the latest version of .NET.
### .NET Core 3.1
Package name | Affected version | Patched version
------------ | ---------------- | --
GHSA
.NET Information Disclosure Vulnerability
ghsa·2024-02-03
CVE-2022-34716 [MEDIUM] .NET Information Disclosure Vulnerability
.NET Information Disclosure Vulnerability
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET Core 3.1 and .NET 6.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
An information disclosure vulnerability exists in .NET Core 3.1 and .NET 6.0 that could lead to unauthorized access of privileged information.
## Affected software
* Any .NET 6.0 application running on .NET 6.0.7 or earlier.
* Any .NET Core 3.1 applicaiton running on .NET Core 3.1.27 or earlier.
If your application uses the following package versions, ensure you update to the latest version of .NET.
### .NET Core 3.1
Package name | Affected version | Patched version
------------ | ---------------- | --
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-08-09
Published