First published: Wed Sep 11 2019(Updated: )
An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project templates, fails to properly sanitize web requests, aka 'ASP.NET Core Elevation Of Privilege Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft ASP.NET Core | =2.1 | |
Microsoft ASP.NET Core | =2.2 | |
Microsoft ASP.NET Core | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1302 is an elevation of privilege vulnerability that exists in ASP.NET Core web applications created using vulnerable project templates.
CVE-2019-1302 has a severity value of 8.8, which is considered high.
The affected software for CVE-2019-1302 includes Microsoft ASP.NET Core versions 2.1, 2.2, and 3.0.
To fix CVE-2019-1302, update your ASP.NET Core web application to a non-vulnerable version.
You can find more information about CVE-2019-1302 at the following reference: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1302