Microsoft.AspNet.Identity.Owin
Owin implementation for ASP.NET Identity.
Activity
- Latest release
- 3y ago
- Total releases
- 14
- Cadence
- ~2 months
- Last 12 months
- 0
Details
- First release
- Aug 23, 2013
| Version | Released | |
|---|---|---|
2.2.4
patch
| ||
2.2.3
patch
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
1.0.0
1.0.0-rc1
2.0.0
2.0.0-alpha1
2.0.0-beta1
2.0.1
2.1.0
2.1.0-alpha1
2.2.0
2.2.0-alpha1
2.2.1
2.2.2
+ 1 more Show less
2.2.3
Fixed in
2.2.4
References
Updated Jun 03, 2024 · Source: OSV.dev | ||
2.2.2
patch
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
1.0.0
1.0.0-rc1
2.0.0
2.0.0-alpha1
2.0.0-beta1
2.0.1
2.1.0
2.1.0-alpha1
2.2.0
2.2.0-alpha1
2.2.1
2.2.2
+ 1 more Show less
2.2.3
Fixed in
2.2.4
References
Updated Jun 03, 2024 · Source: OSV.dev | ||
2.2.1
patch
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
1.0.0
1.0.0-rc1
2.0.0
2.0.0-alpha1
2.0.0-beta1
2.0.1
2.1.0
2.1.0-alpha1
2.2.0
2.2.0-alpha1
2.2.1
2.2.2
+ 1 more Show less
2.2.3
Fixed in
2.2.4
References
Updated Jun 03, 2024 · Source: OSV.dev | ||
2.2.0
minor
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
1.0.0
1.0.0-rc1
2.0.0
2.0.0-alpha1
2.0.0-beta1
2.0.1
2.1.0
2.1.0-alpha1
2.2.0
2.2.0-alpha1
2.2.1
2.2.2
+ 1 more Show less
2.2.3
Fixed in
2.2.4
References
Updated Jun 03, 2024 · Source: OSV.dev | ||
2.2.0-alpha1
pre
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
1.0.0
1.0.0-rc1
2.0.0
2.0.0-alpha1
2.0.0-beta1
2.0.1
2.1.0
2.1.0-alpha1
2.2.0
2.2.0-alpha1
2.2.1
2.2.2
+ 1 more Show less
2.2.3
Fixed in
2.2.4
References
Updated Jun 03, 2024 · Source: OSV.dev | ||
2.1.0
minor
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
1.0.0
1.0.0-rc1
2.0.0
2.0.0-alpha1
2.0.0-beta1
2.0.1
2.1.0
2.1.0-alpha1
2.2.0
2.2.0-alpha1
2.2.1
2.2.2
+ 1 more Show less
2.2.3
Fixed in
2.2.4
References
Updated Jun 03, 2024 · Source: OSV.dev | ||
2.1.0-alpha1
pre
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
1.0.0
1.0.0-rc1
2.0.0
2.0.0-alpha1
2.0.0-beta1
2.0.1
2.1.0
2.1.0-alpha1
2.2.0
2.2.0-alpha1
2.2.1
2.2.2
+ 1 more Show less
2.2.3
Fixed in
2.2.4
References
Updated Jun 03, 2024 · Source: OSV.dev | ||
2.0.1
patch
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
1.0.0
1.0.0-rc1
2.0.0
2.0.0-alpha1
2.0.0-beta1
2.0.1
2.1.0
2.1.0-alpha1
2.2.0
2.2.0-alpha1
2.2.1
2.2.2
+ 1 more Show less
2.2.3
Fixed in
2.2.4
References
Updated Jun 03, 2024 · Source: OSV.dev | ||
2.0.0
major
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
1.0.0
1.0.0-rc1
2.0.0
2.0.0-alpha1
2.0.0-beta1
2.0.1
2.1.0
2.1.0-alpha1
2.2.0
2.2.0-alpha1
2.2.1
2.2.2
+ 1 more Show less
2.2.3
Fixed in
2.2.4
References
Updated Jun 03, 2024 · Source: OSV.dev | ||
2.0.0-beta1
pre
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
1.0.0
1.0.0-rc1
2.0.0
2.0.0-alpha1
2.0.0-beta1
2.0.1
2.1.0
2.1.0-alpha1
2.2.0
2.2.0-alpha1
2.2.1
2.2.2
+ 1 more Show less
2.2.3
Fixed in
2.2.4
References
Updated Jun 03, 2024 · Source: OSV.dev | ||
2.0.0-alpha1
pre
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
1.0.0
1.0.0-rc1
2.0.0
2.0.0-alpha1
2.0.0-beta1
2.0.1
2.1.0
2.1.0-alpha1
2.2.0
2.2.0-alpha1
2.2.1
2.2.2
+ 1 more Show less
2.2.3
Fixed in
2.2.4
References
Updated Jun 03, 2024 · Source: OSV.dev | ||
1.0.0
initial
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
1.0.0
1.0.0-rc1
2.0.0
2.0.0-alpha1
2.0.0-beta1
2.0.1
2.1.0
2.1.0-alpha1
2.2.0
2.2.0-alpha1
2.2.1
2.2.2
+ 1 more Show less
2.2.3
Fixed in
2.2.4
References
Updated Jun 03, 2024 · Source: OSV.dev | ||
1.0.0-rc1
pre
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
1.0.0
1.0.0-rc1
2.0.0
2.0.0-alpha1
2.0.0-beta1
2.0.1
2.1.0
2.1.0-alpha1
2.2.0
2.2.0-alpha1
2.2.1
2.2.2
+ 1 more Show less
2.2.3
Fixed in
2.2.4
References
Updated Jun 03, 2024 · Source: OSV.dev |