CVE-2018-0787
Summary
| CVE | CVE-2018-0787 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-14 17:29:00 UTC |
| Updated | 2018-04-11 15:07:00 UTC |
| Description | ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how web applications that are created from templates validate web requests, aka "ASP.NET Core Elevation Of Privilege Vulnerability". |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| ASP.NET Kestrel Web Application HTML Injection Flaw Lets Remote Users Reset the Target User's Password - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| Microsoft Security Advisory CVE-2018-0787: ASP.NET Core Elevation Of Privilege Vulnerability · Issue #295 · aspnet/Announcements · GitHub |
CONFIRM |
github.com |
Technical Description, Third Party Advisory |
| Microsoft ASP.NET Core CVE-2018-0787 Remote Privilege Escalation Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0787 |
CONFIRM |
portal.msrc.microsoft.com |
Patch, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981395 Dotnet (nuget) Security Update for Microsoft.AspNetCore.Server.Kestrel.Core (GHSA-365p-96qv-xr7g)