CVE-2018-8292
An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1,…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.8%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 14.83% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- microsoft/asp.net core · microsoft/powershell core
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/105548Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:2902Third Party Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8292Patch, Vendor Advisory
- http://www.securityfocus.com/bid/105548Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:2902Third Party Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8292Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.