A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/104659 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1041267 | Third Party Advisory VDB Entry |
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8171 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/104659 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1041267 | Third Party Advisory VDB Entry |
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8171 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2018-07-11 00:29
Updated : 2024-11-21 04:13
NVD link : CVE-2018-8171
Mitre link : CVE-2018-8171
CVE.ORG link : CVE-2018-8171
JSON object : View
Products Affected
microsoft
- asp.net_webpages
- asp.net_model_view_controller
- asp.net_core
CWE
CWE-287
Improper Authentication