PT-2021-7950 · Microsoft+3 · Visual Studio+5

Published

2021-08-10

·

Updated

2024-03-06

·

CVE-2021-34532

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions .NET Core versions 2.1 through 5.0 .NET 5.0 versions prior to 5.0.9 .NET Core 3.1 versions prior to 3.1.18 .NET Core 2.1 versions prior to 2.1.29
Description The issue is related to an information disclosure vulnerability in .NET Core and Visual Studio, where a JWT token is logged if it cannot be parsed. This vulnerability may allow an attacker to disclose protected information.
Recommendations For .NET 5.0, download and install Runtime 5.0.9 or SDK 5.0.206 (for Visual Studio 2019 v16.8) or SDK 5.0.303 (for Visual Studio 2019 V16.10) from https://dotnet.microsoft.com/download/dotnet-core/5.0. For .NET Core 3.1, download and install Runtime 3.1.18 or SDK 3.1.118 (for Visual Studio 2019 v16.4) or 3.1.412 (for Visual Studio 2019 v16.7 or later) from https://dotnet.microsoft.com/download/dotnet-core/3.1. For .NET Core 2.1, download and install Runtime 2.1.29 or SDK 2.1.525 (for Visual Studio 2019 v15.9) or 2.1.817 from https://dotnet.microsoft.com/download/dotnet-core/2.1. If your application is using .NET Core 2.1 running on .NET Framework, check your projects for dependencies and update them accordingly by examining your csproj file or using NuGet to update the dependency.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1269
ALT-PU-2022-1271
ALT-PU-2022-1273
ALT-PU-2022-1277
ALT-PU-2022-1352
ALT-PU-2022-1356
ALT-PU-2022-1357
ALT-PU-2022-1359
ALT-PU-2022-1544
ALT-PU-2022-1546
ALT-PU-2022-1548
ALT-PU-2022-1552
BDU:2023-06552
BIT-ASPNET-CORE-2021-34532
CESA-2021_3142
CESA-2021_3148
CVE-2021-34532
GHSA-Q7CG-43MG-QP69
RHSA-2021:3142
RHSA-2021:3143
RHSA-2021:3147
RHSA-2021:3148
RHSA-2021_3142
RHSA-2021_3148

Affected Products

Alt Linux
Centos
Net Core
.Net Framework
Red Hat
Visual Studio