ASP.NET Core 2.0 allows an attacker to steal log-in session information such as cookies or authentication tokens via a specially crafted URL aka "ASP.NET Core Elevation Of Privilege Vulnerability".
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: microsoft
Published: 2017-11-15T03:00:00Z
Updated: 2024-09-16T22:14:43.416Z
Reserved: 2017-07-31T00:00:00
Link: CVE-2017-11879
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2017-11-15T03:29:01.827
Modified: 2018-02-01T17:06:23.990
Link: CVE-2017-11879
Redhat
No data.