A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka ASP.NET Security Feature Bypass Vulnerability. This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Asp.net_core | Microsoft | 1.0 (including) | 1.0 (including) |
Asp.net_core | Microsoft | 1.1 (including) | 1.1 (including) |
Asp.net_core | Microsoft | 2.0 (including) | 2.0 (including) |
Asp.net_model_view_controller | Microsoft | 5.2 (including) | 5.2 (including) |
Asp.net_webpages | Microsoft | 3.2.3 (including) | 3.2.3 (including) |