CVE Vulnerabilities

CVE-2023-36558

Published: Nov 14, 2023 | Modified: Jan 01, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM

ASP.NET Core Security Feature Bypass Vulnerability

Affected Software

Name Vendor Start Version End Version
.net Microsoft 6.0.0 (including) 6.0.25 (excluding)
.net Microsoft 7.0.0 (including) 7.0.14 (excluding)
.net Microsoft 8.0.0-rc1 (including) 8.0.0-rc1 (including)
.net Microsoft 8.0.0-rc2 (including) 8.0.0-rc2 (including)
Asp.net_core Microsoft 6.0.0 (including) 6.0.25 (excluding)
Asp.net_core Microsoft 7.0.0 (including) 7.0.14 (excluding)
Asp.net_core Microsoft 8.0.0 (including) 8.0.0 (including)
Visual_studio_2022 Microsoft 17.2 (including) 17.2.22 (excluding)
Visual_studio_2022 Microsoft 17.4 (including) 17.4.14 (excluding)
Visual_studio_2022 Microsoft 17.6 (including) 17.6.10 (excluding)
Visual_studio_2022 Microsoft 17.7 (including) 17.7.7 (excluding)
.NET Core on Red Hat Enterprise Linux RedHat rh-dotnet60-dotnet-0:6.0.125-1.el7_9 *
Red Hat Enterprise Linux 8 RedHat dotnet8.0-0:8.0.100-2.el8_9 *
Red Hat Enterprise Linux 8 RedHat dotnet7.0-0:7.0.114-1.el8_9 *
Red Hat Enterprise Linux 8 RedHat dotnet6.0-0:6.0.125-1.el8_9 *
Red Hat Enterprise Linux 9 RedHat dotnet8.0-0:8.0.100-2.el9_3 *
Red Hat Enterprise Linux 9 RedHat dotnet7.0-0:7.0.114-1.el9_3 *
Red Hat Enterprise Linux 9 RedHat dotnet6.0-0:6.0.125-1.el9_3 *
Dotnet6 Ubuntu jammy *
Dotnet6 Ubuntu lunar *
Dotnet6 Ubuntu mantic *
Dotnet6 Ubuntu upstream *
Dotnet7 Ubuntu jammy *
Dotnet7 Ubuntu lunar *
Dotnet7 Ubuntu mantic *
Dotnet7 Ubuntu upstream *
Dotnet8 Ubuntu devel *
Dotnet8 Ubuntu mantic *
Dotnet8 Ubuntu upstream *

References