Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
The authentication scheme or implementation uses key data elements that are assumed to be immutable, but can be controlled or modified by the attacker.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| .net | Microsoft | 8.0.0 (including) | 8.0.29 (excluding) |
| .net | Microsoft | 9.0.0 (including) | 9.0.18 (excluding) |
| Red Hat Enterprise Linux 10 | RedHat | dotnet8.0-0:8.0.129-1.el10_2 | * |
| Red Hat Enterprise Linux 10 | RedHat | dotnet9.0-0:9.0.119-1.el10_2 | * |
| Red Hat Enterprise Linux 10 | RedHat | dotnet10.0-0:10.0.110-1.el10_2 | * |
| Red Hat Enterprise Linux 8 | RedHat | dotnet9.0-0:9.0.119-1.el8_10 | * |
| Red Hat Enterprise Linux 8 | RedHat | dotnet10.0-0:10.0.110-1.el8_10 | * |
| Red Hat Enterprise Linux 8 | RedHat | dotnet8.0-0:8.0.129-1.el8_10 | * |
| Red Hat Enterprise Linux 9 | RedHat | dotnet8.0-0:8.0.129-1.el9_8 | * |
| Red Hat Enterprise Linux 9 | RedHat | dotnet9.0-0:9.0.119-1.el9_8 | * |
| Red Hat Enterprise Linux 9 | RedHat | dotnet10.0-0:10.0.110-1.el9_8 | * |
| Red Hat Hardened Images | RedHat | dotnet10-0-main-10.0.109-1.hum1 | * |
| Red Hat Hardened Images | RedHat | dotnet9-0-main-9.0.118-1.hum1 | * |
| Red Hat Hardened Images | RedHat | dotnet8-0-main-8.0.129-2.1.hum1 | * |
| Dotnet10 | Ubuntu | devel | * |
| Dotnet10 | Ubuntu | noble | * |
| Dotnet10 | Ubuntu | resolute | * |
| Dotnet7 | Ubuntu | jammy | * |
| Dotnet8 | Ubuntu | jammy | * |
| Dotnet8 | Ubuntu | noble | * |