QID 981690
QID 981690: Dotnet (nuget) Security Update for DotNetNuke.Core (GHSA-xx3h-j3cx-8qfj)
DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete fix for CVE-2018-15812.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-xx3h-j3cx-8qfj for updates pertaining to this vulnerability.
Vendor References
- GHSA-xx3h-j3cx-8qfj -
github.com/advisories/GHSA-xx3h-j3cx-8qfj
CVEs related to QID 981690
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xx3h-j3cx-8qfj | DotNetNuke.Core |
|