Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Kévin Chalet

#15329de 53,635
17.6CVSS total
Vulnerabilidades · 2
Alta
2
PT-2018-12881
8.8
2018-08-29
Auth0 · Auth0-Aspnet-Owin · CVE-2018-15121
**Name of the Vulnerable Software and Affected Versions** Auth0 auth0-aspnet and auth0-aspnet-owin (affected versions not specified) **Description** An issue was discovered that leaves applications vulnerable to CSRF attacks during authentication and authorization operations. The affected packages do not use or validate the `state` parameter of the OAuth 2.0 and OpenID Connect protocols. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2018-9065
8.8
2018-01-10
Microsoft · Asp.Net Core · CVE-2018-0784
Name of the Vulnerable Software and Affected Versions: ASP.NET Core versions 1.0 through 2.0 Description: The issue allows an elevation of privilege due to the ASP.NET Core project templates. Recommendations: For ASP.NET Core versions 1.0 through 2.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.