CVE-2018-0808
Summary
| CVE | CVE-2018-0808 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-14 17:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how ASP.NET web applications handle web requests, aka "ASP.NET Core Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0784. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Asp.net Core | 1.0 | All | All | All |
| Application | Microsoft | Asp.net Core | 1.1 | All | All | All |
| Application | Microsoft | Asp.net Core | 2.0 | All | All | All |
| Application | Microsoft | Asp.net Core | 1.0 | All | All | All |
| Application | Microsoft | Asp.net Core | 1.1 | All | All | All |
| Application | Microsoft | Asp.net Core | 2.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft ASP.NET CVE-2018-0808 Denial Of Service Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Microsoft ASP.NET Unspecified Flaw Lets Remote Users Deny Service - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0808 | CONFIRM | portal.msrc.microsoft.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.