cbcvebase.
CVE-2023-35391
published 2023-08-08

CVE-2023-35391: ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability

Affected

18 ranges
VendorProductVersion rangeFixed in
microsoftasp.net_core>= 2.1 < 2.1.402.1.40
microsoftasp.net_core_2.1>= 2.0 < 2.1.402.1.40
microsoftmicrosoft_visual_studio_2022_version_17.2>= 17.2.0 < 17.2.1817.2.18
microsoftmicrosoft_visual_studio_2022_version_17.4>= 17.4.0 < 17.4.1017.4.10
microsoftmicrosoft_visual_studio_2022_version_17.6>= 17.6.0 < 17.6.617.6.6
microsoftnet>= 6.0.0 < 6.0.216.0.21
microsoftnet>= 7.0.0 < 7.0.107.0.10
microsoftnet_6.0>= 6.0.0 < 6.0.216.0.21
microsoftnet_7.0>= 7.0.0 < 7.0.107.0.10
microsoftvisual_studio_2022>= 17.2.0 < 17.2.1817.2.18
microsoftvisual_studio_2022>= 17.4.0 < 17.4.1017.4.10
microsoftvisual_studio_2022>= 17.6.0 < 17.6.617.6.6
msrcasp.net_core_2.1
msrcmicrosoft_visual_studio_2022_version_17.2
msrcmicrosoft_visual_studio_2022_version_17.4
msrcmicrosoft_visual_studio_2022_version_17.6
msrcnet_6.0
msrcnet_7.0

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
ghsa7.5HIGH
osv7.5HIGH