CVE-2017-11879: High severity asp.net core vulnerability
Published Nov 15, 2017
·Updated
ASP.NET Core 2.0 allows an attacker to steal log-in session information such as cookies or authentication tokens via a specially crafted URL aka "ASP.NET Core Elevation Of Privilege Vulnerability".
Affected Software
1 affected component
Microsoft ASP.NET Core=2.0
Remediation
Event History
Nov 15, 2017
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2017-11879?
CVE-2017-11879 is an ASP.NET Core vulnerability that allows an attacker to steal login session information such as cookies or authentication tokens.
2
How does CVE-2017-11879 affect ASP.NET Core 2.0?
CVE-2017-11879 affects ASP.NET Core 2.0 by allowing an attacker to steal login session information through a specially crafted URL.
3
What is the severity of CVE-2017-11879?
CVE-2017-11879 has a severity rating of 8.8 (high).
4
How can an attacker exploit CVE-2017-11879?
An attacker can exploit CVE-2017-11879 by using a specially crafted URL to steal login session information.
5
Is there a fix available for CVE-2017-11879?
Yes, a fix is available for CVE-2017-11879. It is recommended to update to a patched version of ASP.NET Core 2.0.