PT-2019-1123 · Microsoft · .Net Framework+1
Published
2019-01-08
·
Updated
2022-05-23
·
CVE-2019-0545
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
.NET Framework versions 2.0 through 4.7.2
.NET Framework version 3.5
.NET Framework version 3.5.1
.NET Core version 2.1
.NET Core version 2.2
Description:
An information disclosure issue exists in .NET Framework and .NET Core, allowing bypassing of Cross-origin Resource Sharing (CORS) configurations. This could enable an attacker to retrieve normally restricted content from a web application. The vulnerability is related to a lack of protection for service data.
Recommendations:
For .NET Framework versions 2.0 through 4.7.2, update to a version that includes the fix for this issue.
For .NET Framework version 3.5, consider applying configuration changes to restrict access to sensitive data.
For .NET Framework version 3.5.1, apply the recommended security patches.
For .NET Core version 2.1, restrict access to the vulnerable components until a patch is available.
For .NET Core version 2.2, consider disabling the vulnerable functions to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
.Net Framework
Net Core