VYPR
High severityNVD Advisory· Published Jul 11, 2018· Updated Aug 5, 2024

CVE-2018-8171

CVE-2018-8171

Description

A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
Microsoft.AspNetCore.IdentityNuGet
>= 1.0.0, < 1.0.61.0.6
Microsoft.AspNetCore.IdentityNuGet
>= 1.1.0, < 1.1.61.1.6
Microsoft.AspNetCore.IdentityNuGet
>= 2.0.0, < 2.0.42.0.4
Microsoft.AspNetCore.IdentityNuGet
>= 2.1.0, < 2.1.22.1.2

Affected products

3
  • Range: Web Pages 3.2.3 on Microsoft Visual Studio 2013 Update 5
  • Microsoft/ASP.NET Corev5
    Range: 1.0
  • Microsoft/ASP.NET MVC 5.2v5
    Range: Microsoft Visual Studio 2013 Update 5

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.