First published: Wed Jan 10 2018(Updated: )
ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Cross Site Request Forgery Vulnerability".
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft ASP.NET Core | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0785 is a cross site request forgery vulnerability in ASP.NET Core 1.0, 1.1, and 2.0.
CVE-2018-0785 has a severity rating of 6.5, which is considered medium.
ASP.NET Core 2.0 is affected by CVE-2018-0785.
To fix CVE-2018-0785, update ASP.NET Core to a version that is not affected by the vulnerability.
You can find more information about CVE-2018-0785 on the following websites: [SecurityFocus](http://www.securityfocus.com/bid/102379), [SecurityTracker](http://www.securitytracker.com/id/1040151), [Microsoft Security Guidance](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0785).