A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/104659 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1041267 | Third Party Advisory VDB Entry |
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8171 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/104659 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1041267 | Third Party Advisory VDB Entry |
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8171 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:13
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/104659 - Third Party Advisory, VDB Entry | |
References | () http://www.securitytracker.com/id/1041267 - Third Party Advisory, VDB Entry | |
References | () https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8171 - Patch, Vendor Advisory |
Information
Published : 2018-07-11 00:29
Updated : 2024-11-21 04:13
NVD link : CVE-2018-8171
Mitre link : CVE-2018-8171
CVE.ORG link : CVE-2018-8171
JSON object : View
Products Affected
microsoft
- asp.net_model_view_controller
- asp.net_core
- asp.net_webpages
CWE
CWE-287
Improper Authentication