cbcvebase.
CVE-2023-36558
published 2023-11-14

CVE-2023-36558: ASP.NET Core Security Feature Bypass Vulnerability

medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
ASP.NET Core Security Feature Bypass Vulnerability

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftasp.net_core
microsoftasp.net_core>= 6.0.0 < 6.0.256.0.25
microsoftasp.net_core>= 7.0.0 < 7.0.147.0.14
microsoftasp.net_core_6.0>= 6.0 < 6.0.256.0.25
microsoftasp.net_core_7.0>= 7.0.0 < 7.0.147.0.14
microsoftasp.net_core_8.0>= 8.0 < 8.0.08.0.0
microsoftmicrosoft_visual_studio_2022_version_17.2>= 17.2.0 < 17.2.2217.2.22
microsoftmicrosoft_visual_studio_2022_version_17.4>= 17.4.0 < 17.4.1417.4.14
microsoftmicrosoft_visual_studio_2022_version_17.6>= 17.6.0 < 17.6.1017.6.10
microsoftmicrosoft_visual_studio_2022_version_17.7>= 17.7.0 < 17.7.717.7.7
microsoftnet
microsoftnet>= 6.0.0 < 6.0.256.0.25
microsoftnet>= 7.0.0 < 7.0.147.0.14
microsoftnet_6.0>= 6.0.0 < 6.0.256.0.25
microsoftnet_7.0>= 7.0.0 < 7.0.147.0.14
microsoftnet_8.0>= 8.0 < 8.0.08.0.0
microsoftvisual_studio_2022>= 17.2 < 17.2.2217.2.22
microsoftvisual_studio_2022>= 17.4 < 17.4.1417.4.14
microsoftvisual_studio_2022>= 17.6 < 17.6.1017.6.10
microsoftvisual_studio_2022>= 17.7 < 17.7.717.7.7
msrcasp.net_core_6.0
msrcasp.net_core_7.0
msrcasp.net_core_8.0
msrcmicrosoft_visual_studio_2022_version_17.2
msrcmicrosoft_visual_studio_2022_version_17.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
ghsa5.5MEDIUM
osv9.8CRITICAL