Medium severity6.2NVD Advisory· Published Aug 8, 2023· Updated Aug 10, 2026
CVE-2023-35391
CVE-2023-35391
Description
ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Microsoft.AspNetCore.SignalR.StackExchangeRedisNuGet | >= 7.0.0, < 7.0.10 | 7.0.10 |
Microsoft.AspNetCore.SignalR.StackExchangeRedisNuGet | >= 6.0.0, < 6.0.21 | 6.0.21 |
Microsoft.AspNetCore.SignalR.RedisNuGet | < 1.0.40 | 1.0.40 |
Affected products
14- Microsoft/Microsoft Visual Studio 2022 version 17.2v5Range: 17.2.0
- Microsoft/Microsoft Visual Studio 2022 version 17.4v5Range: 17.4.0
- Microsoft/Microsoft Visual Studio 2022 version 17.6v5Range: 17.6.0
- Microsoft/.NET 6.0v5Range: 6.0.0
- Microsoft/.NET 7.0v5Range: 7.0.0
cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*:*range: >=2.1,<2.1.40
- (no CPE)range: 2.0
- cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*Range: >=17.2.0,<17.2.18
- ghsa-coords5 versionspkg:nuget/microsoft.aspnetcore.signalr.stackexchangeredispkg:nuget/microsoft.aspnetcore.signalr.redispkg:bitnami/dotnetpkg:bitnami/dotnet-sdkpkg:bitnami/aspnet-core
>= 7.0.0, < 7.0.10+ 4 more
- (no CPE)range: >= 7.0.0, < 7.0.10
- (no CPE)range: < 1.0.40
- (no CPE)range: >= 6.0.0, < 6.0.21
- (no CPE)range: >= 6.0.0, < 6.0.21
- (no CPE)range: >= 2.1.0, < 2.1.40
Patches
Vulnerability mechanics
References
5- msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35391nvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-j8rm-cm55-qqj6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-35391ghsaADVISORY
- github.com/dotnet/announcements/issues/267ghsaWEB
- github.com/dotnet/aspnetcore/security/advisories/GHSA-j8rm-cm55-qqj6ghsaWEB
News mentions
0No linked articles in our index yet.