First published: Thu Oct 04 2018(Updated: )
An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft ASP.NET Core | =1.0 | |
Microsoft ASP.NET Core | =1.1 | |
Microsoft ASP.NET Core | =2.1 | |
Microsoft Powershell Core | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8292 is an information disclosure vulnerability in .NET Core and PowerShell Core where authentication information is inadvertently exposed in a redirect.
CVE-2018-8292 affects .NET Core versions 2.1, 1.1, and 1.0.
CVE-2018-8292 affects PowerShell Core version 6.0.
CVE-2018-8292 has a severity level of high, with a CVSS score of 7.5.
To fix CVE-2018-8292, update to the latest version of .NET Core or PowerShell Core.