CVE-2023-36558
Description
ASP.NET Core Security Feature Bypass Vulnerability
CWE
- (none)
Affected
- Microsoft / .NET 6.0 — v=6.0.0 <6.0.25 [affected]
- Microsoft / ASP.NET Core 6.0 — v=6.0 <6.0.25 [affected]
- Microsoft / .NET 7.0 — v=7.0.0 <7.0.14 [affected]
- Microsoft / Microsoft Visual Studio 2022 version 17.2 — v=17.2.0 <17.2.22 [affected]
- Microsoft / .NET 8.0 — v=8.0 <8.0.0 [affected]
- Microsoft / Microsoft Visual Studio 2022 version 17.4 — v=17.4.0 <17.4.14 [affected]
- Microsoft / Microsoft Visual Studio 2022 version 17.6 — v=17.6.0 <17.6.10 [affected]
- Microsoft / Microsoft Visual Studio 2022 version 17.7 — v=17.7.0 <17.7.7 [affected]
- Microsoft / ASP.NET Core 7.0 — v=7.0.0 <7.0.14 [affected]
- Microsoft / ASP.NET Core 8.0 — v=8.0 <8.0.0 [affected]
CVSS
- 3.1 score=6.2 severity=MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C
References
Source
cvelistV5-main/cves/2023/36xxx/CVE-2023-36558.json