CVE-2018-8292: Infoleak
A flaw was found in .NET Core. An information disclosure vulnerability in a redirect when authentication information has been added manually to an Authorization header. An attacker who successfully exploited this vulnerability could use the information to further compromise the web application.
Other sources
An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-8292?
CVE-2018-8292 is an information disclosure vulnerability in .NET Core and PowerShell Core where authentication information is inadvertently exposed in a redirect.
How does CVE-2018-8292 affect .NET Core?
CVE-2018-8292 affects .NET Core versions 2.1, 1.1, and 1.0.
How does CVE-2018-8292 affect PowerShell Core?
CVE-2018-8292 affects PowerShell Core version 6.0.
What is the severity of CVE-2018-8292?
CVE-2018-8292 has a severity level of high, with a CVSS score of 7.5.
How can I fix CVE-2018-8292?
To fix CVE-2018-8292, update to the latest version of .NET Core or PowerShell Core.