PT-2019-1123 · Microsoft · .Net Framework+1

Publicado

2019-01-08

·

Atualizado

2022-05-23

·

CVE-2019-0545

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: .NET Framework versions 2.0 through 4.7.2 .NET Framework version 3.5 .NET Framework version 3.5.1 .NET Core version 2.1 .NET Core version 2.2
Description: An information disclosure issue exists in .NET Framework and .NET Core, allowing bypassing of Cross-origin Resource Sharing (CORS) configurations. This could enable an attacker to retrieve normally restricted content from a web application. The vulnerability is related to a lack of protection for service data.
Recommendations: For .NET Framework versions 2.0 through 4.7.2, update to a version that includes the fix for this issue. For .NET Framework version 3.5, consider applying configuration changes to restrict access to sensitive data. For .NET Framework version 3.5.1, apply the recommended security patches. For .NET Core version 2.1, restrict access to the vulnerable components until a patch is available. For .NET Core version 2.2, consider disabling the vulnerable functions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-00149
CVE-2019-0545
GHSA-2XJX-V99W-GQF3
RHSA-2019:0040

Produtos afetados

.Net Framework
Net Core