Nov 2023: ASP.NET Core Security Feature Bypass Vulnerability
CVE-2023-36558 Published on November 14, 2023

ASP.NET Core Security Feature Bypass Vulnerability
ASP.NET Core Security Feature Bypass Vulnerability

Github Repository Vendor Advisory NVD


Products Associated with CVE-2023-36558

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2023-36558 are published in these products:

 
 
 
 
 

Affected Versions

Microsoft .NET 6.0: Microsoft ASP.NET Core 6.0: Microsoft .NET 7.0: Microsoft Visual Studio 2022 version 17.2: Microsoft .NET 8.0: Microsoft Visual Studio 2022 version 17.4: Microsoft Visual Studio 2022 version 17.6: Microsoft Visual Studio 2022 version 17.7: Microsoft ASP.NET Core 7.0: Microsoft ASP.NET Core 8.0:

Vulnerable Packages

The following package name and versions may be associated with CVE-2023-36558

Package Manager Vulnerable Package Versions Fixed In
nuget Microsoft.AspNetCore.Components >= 6.0.0, <= 6.0.24 6.0.25
nuget Microsoft.AspNetCore.Components >= 7.0.0, <= 7.0.13 7.0.14
nuget Microsoft.AspNetCore.Components = 8.0.0-rc.2.23480.2 8.0.0

Exploit Probability

EPSS
0.35%
Percentile
56.93%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.