Microsoft ASP.NET Core SignalR & VS Info Disclosure (CVE-2023-35391)
CVE-2023-35391 Published on August 8, 2023

ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability

Github Repository Vendor Advisory NVD


Products Associated with CVE-2023-35391

Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.

 
 
 

Affected Versions

Microsoft Visual Studio 2022 version 17.2: Microsoft Visual Studio 2022 version 17.4: Microsoft Visual Studio 2022 version 17.6: Microsoft ASP.NET Core 2.1: Microsoft .NET 6.0: Microsoft .NET 7.0:

Vulnerable Packages

The following package name and versions may be associated with CVE-2023-35391

Package Manager Vulnerable Package Versions Fixed In
nuget Microsoft.AspNetCore.SignalR.StackExchangeRedis >= 7.0.0, <= 7.0.9 7.0.10
nuget Microsoft.AspNetCore.SignalR.StackExchangeRedis >= 6.0.0, <= 6.0.20 6.0.21
nuget Microsoft.AspNetCore.SignalR.Redis < 1.0.40 1.0.40

Exploit Probability

EPSS
2.61%
Percentile
85.42%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.