A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2.
References
Link | Resource |
---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8171 | Vendor Advisory Patch |
http://www.securitytracker.com/id/1041267 | Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/104659 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2018-07-10 17:29
Updated : 2021-06-30 09:52
NVD link : CVE-2018-8171
Mitre link : CVE-2018-8171
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
microsoft
- asp.net_model_view_controller
- asp.net_webpages
- asp.net_core