CVE-2021-34532: ASP.NET Core and Visual Studio Information Disclosure Vulnerability
ASP.NET Core and Visual Studio Information Disclosure Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.4.25 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.10.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.7.18 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.9.10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.1.29 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.1.18 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.10.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.0.9
Event History
Frequently Asked Questions
What is CVE-2021-34532?
CVE-2021-34532 is an Information Disclosure vulnerability in ASP.NET Core and Visual Studio.
Which software is affected by CVE-2021-34532?
Microsoft ASP.NET Core versions 2.1, 3.1, and 5.0, as well as Microsoft Visual Studio 2019 versions 16.0 and 16.10 are affected by CVE-2021-34532.
What is the severity of CVE-2021-34532?
CVE-2021-34532 has a severity rating of 5.5 (medium).
How can I fix the CVE-2021-34532 vulnerability?
To fix the CVE-2021-34532 vulnerability, it is recommended to update to the latest versions of Microsoft ASP.NET Core and Microsoft Visual Studio 2019.
Where can I get more information about CVE-2021-34532?
You can find more information about CVE-2021-34532 on the Microsoft Security Portal: [CVE-2021-34532](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-34532).