Microsoft.AspNetCore.Identity
ASP.NET Core Identity is the membership system for building ASP.NET Core web applications, including membership, login, and user data. ASP.NET Core Identity allows you to add login features to your application and makes it easy to customize data about the logged in user.
Activity
- Latest release
- 1mo ago
- Total releases
- 44
- Cadence
- ~26 days
- Last 12 months
- 5
Details
- First release
- May 16, 2016
| Version | Released | |
|---|---|---|
2.3.12
patch
|
2.3.12
patch
Dependencies (5)
|
|
2.3.11
patch
|
2.3.11
patch
Dependencies (4)
|
|
2.3.10
patch
|
2.3.10
patch
Dependencies (4)
|
|
2.3.9
patch
|
2.3.9
patch
Dependencies (4)
|
|
2.3.8
patch
|
2.3.8
patch
Dependencies (4)
|
|
2.3.1
patch
|
2.3.1
patch
Dependencies (4)
|
|
2.3.0
minor
1 CVE
CVE-2025-24070
GHSA-2865-hh9g-w894
BIT-aspnet-core-2025-24070
Mar 11, 2025
Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege Vulnerability
7.0
/ 10
High
Network
High
None
None
Unchanged
Low
Low
High
Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 9.0, ASP.NET Core 8.0, ASP.NET Core 6.0, and ASP.NET Core 2.3. This advisory also provides guidance on what developers can do to update their applications to address this vulnerability. A vulnerability exists in ASP.NET Core applications calling RefreshSignInAsync with an improperly authenticated user parameter that could allow an attacker to sign into another user's account, resulting in Elevation of Privilege. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/348 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
Affected PackagesThe vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below | Package name | Affected version | Patched version | | --- | --- | --- | | Microsoft.AspNetCore.Identity | 2.3.0 | 2.3.1 | ASP.NET Core 9| Package name | Affected version | Patched version | | --- | --- | --- | | Microsoft.AspNetCore.App.Runtime.linux-arm | >= 9.0.0, <= 9.0.2 | 9.0.3 | | Microsoft.AspNetCore.App.Runtime.linux-arm64 | >= 9.0.0, <= 9.0.2 | 9.0.3 | | Microsoft.AspNetCore.App.Runtime.linux-musl-arm | >= 9.0.0, <= 9.0.2 | 9.0.3 | | Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | >= 9.0.0, <= 9.0.2 | 9.0.3 | | Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | >= 9.0.0, <= 9.0.2 | 9.0.3 | | Microsoft.AspNetCore.App.Runtime.linux-x64 | >= 9.0.0, <= 9.0.2 | 9.0.3 | | Microsoft.AspNetCore.App.Runtime.osx-arm64 | >= 9.0.0, <= 9.0.2 | 9.0.3 | | Microsoft.AspNetCore.App.Runtime.osx-x64 | >= 9.0.0, <= 9.0.2 | 9.0.3 | | Microsoft.AspNetCore.App.Runtime.win-arm | >= 9.0.0, <= 9.0.2 | 9.0.3 | | Microsoft.AspNetCore.App.Runtime.win-arm64 | >= 9.0.0, <= 9.0.2 | 9.0.3 | | Microsoft.AspNetCore.App.Runtime.win-x64 | >= 9.0.0, <= 9.0.2 | 9.0.3 | | Microsoft.AspNetCore.App.Runtime.win-x86 | >= 9.0.0, <= 9.0.2 | 9.0.3 | ASP.NET Core 8| Package name | Affected version | Patched version | | --- | --- | --- | | Microsoft.AspNetCore.App.Runtime.linux-arm | >= 8.0.0, <= 8.0.13 | 8.0.14 | | Microsoft.AspNetCore.App.Runtime.linux-arm64 | >= 8.0.0, <= 8.0.13 | 8.0.14 | | Microsoft.AspNetCore.App.Runtime.linux-musl-arm | >= 8.0.0, <= 8.0.13 | 8.0.14 | | Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | >= 8.0.0, <= 8.0.13 | 8.0.14 | | Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | >= 8.0.0, <= 8.0.13 | 8.0.14 | | Microsoft.AspNetCore.App.Runtime.linux-x64 | >= 8.0.0, <= 8.0.13 | 8.0.14 | | Microsoft.AspNetCore.App.Runtime.osx-arm64 | >= 8.0.0, <= 8.0.13 | 8.0.14 | | Microsoft.AspNetCore.App.Runtime.osx-x64 | >= 8.0.0, <= 8.0.13 | 8.0.14 | | Microsoft.AspNetCore.App.Runtime.win-arm | >= 8.0.0, <= 8.0.13 | 8.0.14 | | Microsoft.AspNetCore.App.Runtime.win-arm64 | >= 8.0.0, <= 8.0.13 | 8.0.14 | | Microsoft.AspNetCore.App.Runtime.win-x64 | >= 8.0.0, <= 8.0.13 | 8.0.14 | | Microsoft.AspNetCore.App.Runtime.win-x86 | >= 8.0.0, <= 8.0.13 | 8.0.14 | ASP.NET Core 6| Package name | Affected version | Patched version | | --- | --- | --- | | Microsoft.AspNetCore.App.Runtime.linux-arm | >= 6.0.0, <= 6.0.36 | none | | Microsoft.AspNetCore.App.Runtime.linux-arm64 | >= 6.0.0, <= 6.0.36 | none | | Microsoft.AspNetCore.App.Runtime.linux-musl-arm | >= 6.0.0, <= 6.0.36 | none | | Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | >= 6.0.0, <= 6.0.36 | none | | Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | >= 6.0.0, <= 6.0.36 | none | | Microsoft.AspNetCore.App.Runtime.linux-x64 | >= 6.0.0, <= 6.0.36 | none | | Microsoft.AspNetCore.App.Runtime.osx-arm64 | >= 6.0.0, <= 6.0.36 | none | | Microsoft.AspNetCore.App.Runtime.osx-x64 | >= 6.0.0, <= 6.0.36 | none | | Microsoft.AspNetCore.App.Runtime.win-arm | >= 6.0.0, <= 6.0.36 | none | | Microsoft.AspNetCore.App.Runtime.win-arm64 | >= 6.0.0, <= 6.0.36 | none | | Microsoft.AspNetCore.App.Runtime.win-x64 | >= 6.0.0, <= 6.0.36 | none | | Microsoft.AspNetCore.App.Runtime.win-x86 | >= 6.0.0, <= 6.0.36 | none | Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software or affected packages, you're exposed to the vulnerability. How do I fix the issue?
Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 8.0 or .NET 9.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/aspnetcore. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksAcknowledgementZahid TOKAT Affected versions
2.3.0
Fixed in
2.3.1
References Updated Oct 23, 2025 · Source: OSV.dev |
2.3.0
minor
Dependencies (4)
|
|
2.1.39
patch
|
2.1.39
patch
Dependencies (4)
|
|
2.1.31
patch
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev |
2.1.31
patch
Dependencies (4)
|
|
2.2.0
minor
|
2.2.0
minor
Dependencies (4)
|
|
2.1.6
patch
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev |
2.1.6
patch
Dependencies (4)
|
|
2.2.0-preview3-35497
pre
|
2.2.0-preview3-35497
pre
Dependencies (4)
|
|
2.2.0-preview2-35157
pre
|
2.2.0-preview2-35157
pre
Dependencies (4)
|
|
2.2.0-preview1-35029
pre
|
2.2.0-preview1-35029
pre
Dependencies (4)
|
|
2.1.3
patch
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev |
2.1.3
patch
Dependencies (4)
|
|
2.1.2
patch
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev |
2.1.2
patch
Dependencies (4)
|
|
2.0.4
patch
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev |
2.0.4
patch
Dependencies (4)
|
|
1.1.6
patch
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev |
1.1.6
patch
Dependencies (4)
|
|
1.0.6
patch
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev |
1.0.6
patch
Dependencies (5)
|
|
2.1.1
patch
2 CVEs
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2018-8171
GHSA-vhvh-528q-ff3p
Oct 16, 2018
Security feature bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
+ 6 more Show less
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
Fixed in
1.0.6
1.1.6
2.0.4
2.1.2
References Updated Nov 08, 2023 · Source: OSV.dev |
2.1.1
patch
Dependencies (4)
|
|
2.1.0
minor
2 CVEs
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2018-8171
GHSA-vhvh-528q-ff3p
Oct 16, 2018
Security feature bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
+ 6 more Show less
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
Fixed in
1.0.6
1.1.6
2.0.4
2.1.2
References Updated Nov 08, 2023 · Source: OSV.dev |
2.1.0
minor
Dependencies (4)
|
|
2.0.3
patch
2 CVEs
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2018-8171
GHSA-vhvh-528q-ff3p
Oct 16, 2018
Security feature bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
+ 6 more Show less
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
Fixed in
1.0.6
1.1.6
2.0.4
2.1.2
References Updated Nov 08, 2023 · Source: OSV.dev |
2.0.3
patch
Dependencies (4)
|
|
2.1.0-rc1-final
pre
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev |
2.1.0-rc1-final
pre
Dependencies (4)
|
|
2.1.0-preview2-final
pre
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev |
2.1.0-preview2-final
pre
Dependencies (4)
|
|
2.0.2
patch
2 CVEs
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2018-8171
GHSA-vhvh-528q-ff3p
Oct 16, 2018
Security feature bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
+ 6 more Show less
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
Fixed in
1.0.6
1.1.6
2.0.4
2.1.2
References Updated Nov 08, 2023 · Source: OSV.dev |
2.0.2
patch
Dependencies (4)
|
|
2.1.0-preview1-final
pre
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev |
2.1.0-preview1-final
pre
Dependencies (4)
|
|
1.1.5
patch
2 CVEs
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2018-8171
GHSA-vhvh-528q-ff3p
Oct 16, 2018
Security feature bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
+ 6 more Show less
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
Fixed in
1.0.6
1.1.6
2.0.4
2.1.2
References Updated Nov 08, 2023 · Source: OSV.dev |
1.1.5
patch
Dependencies (4)
|
|
2.0.1
patch
2 CVEs
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2018-8171
GHSA-vhvh-528q-ff3p
Oct 16, 2018
Security feature bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
+ 6 more Show less
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
Fixed in
1.0.6
1.1.6
2.0.4
2.1.2
References Updated Nov 08, 2023 · Source: OSV.dev |
2.0.1
patch
Dependencies (4)
|
|
1.1.4
patch
2 CVEs
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2018-8171
GHSA-vhvh-528q-ff3p
Oct 16, 2018
Security feature bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
+ 6 more Show less
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
Fixed in
1.0.6
1.1.6
2.0.4
2.1.2
References Updated Nov 08, 2023 · Source: OSV.dev |
1.1.4
patch
Dependencies (4)
|
|
1.0.5
patch
2 CVEs
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2018-8171
GHSA-vhvh-528q-ff3p
Oct 16, 2018
Security feature bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
+ 6 more Show less
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
Fixed in
1.0.6
1.1.6
2.0.4
2.1.2
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.5
patch
Dependencies (4)
|
|
1.1.3
patch
2 CVEs
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2018-8171
GHSA-vhvh-528q-ff3p
Oct 16, 2018
Security feature bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
+ 6 more Show less
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
Fixed in
1.0.6
1.1.6
2.0.4
2.1.2
References Updated Nov 08, 2023 · Source: OSV.dev |
1.1.3
patch
Dependencies (4)
|
|
1.0.4
patch
2 CVEs
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2018-8171
GHSA-vhvh-528q-ff3p
Oct 16, 2018
Security feature bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
+ 6 more Show less
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
Fixed in
1.0.6
1.1.6
2.0.4
2.1.2
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.4
patch
Dependencies (4)
|
|
2.0.0
major
2 CVEs
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2018-8171
GHSA-vhvh-528q-ff3p
Oct 16, 2018
Security feature bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
+ 6 more Show less
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
Fixed in
1.0.6
1.1.6
2.0.4
2.1.2
References Updated Nov 08, 2023 · Source: OSV.dev |
2.0.0
major
Dependencies (4)
|
|
2.0.0-preview2-final
pre
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev |
2.0.0-preview2-final
pre
Dependencies (4)
|
|
2.0.0-preview1-final
pre
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev |
2.0.0-preview1-final
pre
Dependencies (5)
|
|
1.1.2
patch
2 CVEs
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2018-8171
GHSA-vhvh-528q-ff3p
Oct 16, 2018
Security feature bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
+ 6 more Show less
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
Fixed in
1.0.6
1.1.6
2.0.4
2.1.2
References Updated Nov 08, 2023 · Source: OSV.dev |
1.1.2
patch
Dependencies (4)
|
|
1.0.3
patch
2 CVEs
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2018-8171
GHSA-vhvh-528q-ff3p
Oct 16, 2018
Security feature bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
+ 6 more Show less
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
Fixed in
1.0.6
1.1.6
2.0.4
2.1.2
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.3
patch
Dependencies (4)
|
|
1.1.1
patch
2 CVEs
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2018-8171
GHSA-vhvh-528q-ff3p
Oct 16, 2018
Security feature bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
+ 6 more Show less
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
Fixed in
1.0.6
1.1.6
2.0.4
2.1.2
References Updated Nov 08, 2023 · Source: OSV.dev |
1.1.1
patch
Dependencies (4)
|
|
1.0.2
patch
2 CVEs
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2018-8171
GHSA-vhvh-528q-ff3p
Oct 16, 2018
Security feature bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
+ 6 more Show less
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
Fixed in
1.0.6
1.1.6
2.0.4
2.1.2
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.2
patch
Dependencies (4)
|
|
1.0.1
patch
2 CVEs
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2018-8171
GHSA-vhvh-528q-ff3p
Oct 16, 2018
Security feature bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
+ 6 more Show less
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
Fixed in
1.0.6
1.1.6
2.0.4
2.1.2
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.1
patch
Dependencies (4)
|
|
1.1.0
minor
2 CVEs
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2018-8171
GHSA-vhvh-528q-ff3p
Oct 16, 2018
Security feature bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
+ 6 more Show less
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
Fixed in
1.0.6
1.1.6
2.0.4
2.1.2
References Updated Nov 08, 2023 · Source: OSV.dev |
1.1.0
minor
Dependencies (4)
|
|
1.1.0-preview1-final
pre
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev |
1.1.0-preview1-final
pre
Dependencies (4)
|
|
1.0.0
initial
2 CVEs
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2018-8171
GHSA-vhvh-528q-ff3p
Oct 16, 2018
Security feature bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
+ 6 more Show less
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
Fixed in
1.0.6
1.1.6
2.0.4
2.1.2
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.0
initial
Dependencies (4)
|
|
1.0.0-rc2-final
pre
1 CVE
CVE-2023-33170
GHSA-25c8-p796-jg6r
BIT-dotnet-2023-33170
BIT-dotnet-sdk-2023-33170
Jul 11, 2023
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityExecutive summaryMicrosoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords. DiscussionDiscussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334 Mitigation factorsMicrosoft has not identified any mitigating factors for this vulnerability. Affected software
If your application uses the following package versions, ensure you update to the latest version of .NET. ASP.NET Core 2.1Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.Identity | <=2.1.39 | 2.1.39 Microsoft.AspNet.Identity.OwinPackage name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNet.Identity.Owin | <= 2.2.3 | 2.2.4 ASP.NET 6.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 6.0.19 | 6.0.20 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 6.0.19 | 6.0.20 ASP.NET 7.0Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.App.Runtime.linux-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.linux-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.osx-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-arm64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x64 | <= 7.0.9 | 7.0.9 Microsoft.AspNetCore.App.Runtime.win-x86 | <= 7.0.9 | 7.0.9 Advisory FAQHow do I know if I am affected?If you have a runtime or SDK with a version listed, or an affected package listed in affected software, you're exposed to the vulnerability. How do I fix the issue?
.NET 6.0 and and .NET 7.0 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates. Once you have installed the updated runtime or SDK, restart your apps for the update to take effect. Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. Other InformationReporting Security IssuesIf you have found a potential security issue in .NET 6.0 or .NET 7.0, please email details to secure@microsoft.com. Reports may qualify for the Microsoft .NET Core & .NET 5 Bounty. Details of the Microsoft .NET Bounty Program including terms and conditions are at https://aka.ms/corebounty. SupportYou can ask questions about this issue on GitHub in the .NET GitHub organization. The main repos are located at https://github.com/dotnet/runtime and https://github.com/dotnet/aspnet/. The Announcements repo (https://github.com/dotnet/Announcements) will contain this bulletin as an issue and will include a link to a discussion issue. You can ask questions in the linked discussion issue. DisclaimerThe information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. External LinksRevisionsV1.0 (July 11, 2023): Advisory published. Version 1.0 Last Updated 2023-07-11 Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.0-preview1-final
1.1.1
+ 21 more Show less
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.0.0
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.2
2.1.3
2.1.31
2.1.6
Fixed in
2.1.39
References
Updated Jun 03, 2024 · Source: OSV.dev |
1.0.0-rc2-final
pre
Dependencies (4)
|