{"id":"GHSA-7jgj-8wvc-jh57","summary":".NET Core Information Disclosure","details":"An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka \".NET Core Information Disclosure Vulnerability.\" This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0.","aliases":["CVE-2018-8292"],"modified":"2023-11-08T04:00:26.990614Z","published":"2021-04-21T19:16:06Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-200"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-04-21T19:15:50Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-8292"},{"type":"WEB","url":"https://github.com/dotnet/announcements/issues/88"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:2902"},{"type":"WEB","url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8292"},{"type":"WEB","url":"http://www.securityfocus.com/bid/105548"}],"affected":[{"package":{"name":"System.Net.Http","ecosystem":"NuGet","purl":"pkg:nuget/System.Net.Http"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.3.4"}]}],"versions":["2.0.20126.16343","2.0.20505","2.0.20710","4.0.0","4.0.0-beta-22231","4.0.0-beta-22416","4.0.0-beta-22605","4.0.0-beta-22816","4.0.0-beta-23019","4.0.0-beta-23109","4.0.1-beta-23225","4.0.1-beta-23409","4.0.1-beta-23516","4.0.1-rc2-24027","4.1.0","4.1.1","4.1.2","4.1.3","4.1.4","4.3.0","4.3.0-preview1-24530-04","4.3.1","4.3.2","4.3.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-7jgj-8wvc-jh57/GHSA-7jgj-8wvc-jh57.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}