Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| Microsoft.AspNetCore.Identity(NuGet) | 2.3.0 | 2.3.1 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-arm(NuGet) | 9.0.0 | 9.0.3 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-arm(NuGet) | 8.0.0 | 8.0.14 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-arm64(NuGet) | 9.0.0 | 9.0.3 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-arm64(NuGet) | 8.0.0 | 8.0.14 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-musl-arm(NuGet) | 9.0.0 | 9.0.3 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-musl-arm(NuGet) | 8.0.0 | 8.0.14 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-musl-arm64(NuGet) | 9.0.0 | 9.0.3 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-musl-arm64(NuGet) | 8.0.0 | 8.0.14 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-musl-x64(NuGet) | 9.0.0 | 9.0.3 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-musl-x64(NuGet) | 8.0.0 | 8.0.14 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-x64(NuGet) | 9.0.0 | 9.0.3 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-x64(NuGet) | 8.0.0 | 8.0.14 | N/A |
| Microsoft.AspNetCore.App.Runtime.osx-arm64(NuGet) | 9.0.0 | 9.0.3 | N/A |
| Microsoft.AspNetCore.App.Runtime.osx-arm64(NuGet) | 8.0.0 | 8.0.14 | N/A |
| Microsoft.AspNetCore.App.Runtime.osx-x64(NuGet) | 9.0.0 | 9.0.3 | N/A |
| Microsoft.AspNetCore.App.Runtime.osx-x64(NuGet) | 8.0.0 | 8.0.14 | N/A |
| Microsoft.AspNetCore.App.Runtime.win-arm(NuGet) | 8.0.0 | 8.0.14 | N/A |
| Microsoft.AspNetCore.App.Runtime.win-arm(NuGet) | 9.0.0 | 9.0.3 | N/A |
| Microsoft.AspNetCore.App.Runtime.win-arm64(NuGet) | 9.0.0 | 9.0.3 | N/A |
| Microsoft.AspNetCore.App.Runtime.win-arm64(NuGet) | 8.0.0 | 8.0.14 | N/A |
| Microsoft.AspNetCore.App.Runtime.win-x64(NuGet) | 9.0.0 | 9.0.3 | N/A |
| Microsoft.AspNetCore.App.Runtime.win-x64(NuGet) | 8.0.0 | 8.0.14 | N/A |
| Microsoft.AspNetCore.App.Runtime.win-x86(NuGet) | 8.0.0 | 8.0.14 | N/A |
| Microsoft.AspNetCore.App.Runtime.win-x86(NuGet) | 9.0.0 | 9.0.3 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-arm(NuGet) | 6.0.0 | N/A | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-arm64(NuGet) | 6.0.0 | N/A | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-musl-arm(NuGet) | 6.0.0 | N/A | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-musl-arm64(NuGet) | 6.0.0 | N/A | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-musl-x64(NuGet) | 6.0.0 | N/A | N/A |
| Microsoft.AspNetCore.App.Runtime.osx-arm64(NuGet) | 6.0.0 | N/A | N/A |
| Microsoft.AspNetCore.App.Runtime.osx-x64(NuGet) | 6.0.0 | N/A | N/A |
| Microsoft.AspNetCore.App.Runtime.win-arm(NuGet) | 6.0.0 | N/A | N/A |
| Microsoft.AspNetCore.App.Runtime.win-arm64(NuGet) | 6.0.0 | N/A | N/A |
| Microsoft.AspNetCore.App.Runtime.win-x64(NuGet) | 6.0.0 | N/A | N/A |
| Microsoft.AspNetCore.App.Runtime.win-x86(NuGet) | 6.0.0 | N/A | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-x64(NuGet) | 6.0.0 | N/A | N/A |
CVSS Metrics