CVE-2018-8292High

.NET Core Information Disclosure Vulnerability

Published
October 9, 2018
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect. An attacker who successfully exploited this vulnerability could use the information to further compromise the web application. The security update addresses the vulnerability by correcting how .NET Core handles redirects.

🎯 Affected products4

  • .NET Core 1.0
  • .NET Core 1.1
  • .NET Core 2.1
  • PowerShell Core 6.0

✅ Remediation

KBCommit (Security Update) KBRelease Notes (Security Update)

🔗 References (4)