CVE-2023-36558

9 documents7 sources
Severity
5.5MEDIUM
EPSS
0.3%
top 42.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 14
Latest updateNov 15

Description

ASP.NET Core Security Feature Bypass Vulnerability

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.5 | Impact: 3.6

Affected Packages16 packages

NVDmicrosoft/asp.net_core6.0.06.0.25+2
CVEListV5microsoft/asp.net_core_6.06.06.0.25
CVEListV5microsoft/asp.net_core_7.07.0.07.0.14
CVEListV5microsoft/asp.net_core_8.08.08.0.0
NuGetMicrosoft.AspNetCore.Components8.0.0-rc.2.23480.28.0.0+2

Patches

🔴Vulnerability Details

5
OSV
dotnet6, dotnet7, dotnet8 vulnerabilities2023-11-15
OSV
Microsoft Security Advisory CVE-2023-36558: .NET Security Feature Bypass Vulnerability2023-11-14
CVEList
ASP.NET Core Security Feature Bypass Vulnerability2023-11-14
OSV
CVE-2023-36558: ASP2023-11-14
GHSA
Microsoft Security Advisory CVE-2023-36558: .NET Security Feature Bypass Vulnerability2023-11-14

📋Vendor Advisories

3
Ubuntu
.NET vulnerabilities2023-11-15
Red Hat
dotnet: ASP.NET Security Feature Bypass Vulnerability in Blazor forms2023-11-14
Microsoft
ASP.NET Core Security Feature Bypass Vulnerability2023-11-14
CVE-2023-36558 (MEDIUM CVSS 5.5) | ASP.NET Core Security Feature Bypas | cvebase.io