Description
ASP.NET and Visual Studio Security Feature Bypass Vulnerability
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9Attack Vector: Network
Complexity: High
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: High
Availability: High
Affected Packages21 packages
Also affects: Fedora 37, 38
🔴Vulnerability Details
4CVEListASP.NET and Visual Studio Security Feature Bypass Vulnerability↗2023-07-11 ▶ GHSAMicrosoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability↗2023-07-11 ▶ OSVMicrosoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability↗2023-07-11 ▶ OSVCVE-2023-33170: ASP↗2023-07-11 ▶ 📋Vendor Advisories
3Ubuntu.NET vulnerability↗2023-07-11 ▶ MicrosoftASP.NET and Visual Studio Security Feature Bypass Vulnerability↗2023-07-11 ▶ Red Hatdotnet: race condition in Core SignInManager<TUser> PasswordSignInAsync method↗2023-07-11 ▶