microsoft.aspnetcore.identity.entityframeworkcore.2.1.1.nupkg: 2 vulnerabilities (highest severity is: 8.1) #36
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
Vulnerable Library - microsoft.aspnetcore.identity.entityframeworkcore.2.1.1.nupkg
Path to dependency file: /electricity.csproj
Path to vulnerable library: /home/wss-scanner/.nuget/packages/microsoft.aspnetcore.identity/2.1.1/microsoft.aspnetcore.identity.2.1.1.nupkg
Found in HEAD commit: b984cd05e6d24e7f9d2e92ad8183e9a4a732743c
Vulnerabilities
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2023-33170
Vulnerable Library - microsoft.aspnetcore.identity.2.1.1.nupkg
ASP.NET Core Identity is the membership system for building ASP.NET Core web applications, including membership, login, and user data.
Library home page: https://api.nuget.org/packages/microsoft.aspnetcore.identity.2.1.1.nupkg
Path to dependency file: /electricity.csproj
Path to vulnerable library: /home/wss-scanner/.nuget/packages/microsoft.aspnetcore.identity/2.1.1/microsoft.aspnetcore.identity.2.1.1.nupkg
Dependency Hierarchy:
Found in HEAD commit: b984cd05e6d24e7f9d2e92ad8183e9a4a732743c
Found in base branch: master
Vulnerability Details
ASP.NET and Visual Studio Security Feature Bypass Vulnerability
Publish Date: 2023-07-11
URL: CVE-2023-33170
CVSS 3 Score Details (8.1)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-25c8-p796-jg6r
Release Date: 2023-07-11
Fix Resolution: Microsoft.AspNet.Identity.Owin - 2.2.4;Microsoft.AspNetCore.App.Runtime - 6.0.20,7.0.9;Microsoft.AspNetCore.Identity - 2.1.39
Step up your Open Source Security Game with Mend here
CVE-2018-8171
Vulnerable Library - microsoft.aspnetcore.identity.2.1.1.nupkg
ASP.NET Core Identity is the membership system for building ASP.NET Core web applications, including membership, login, and user data.
Library home page: https://api.nuget.org/packages/microsoft.aspnetcore.identity.2.1.1.nupkg
Path to dependency file: /electricity.csproj
Path to vulnerable library: /home/wss-scanner/.nuget/packages/microsoft.aspnetcore.identity/2.1.1/microsoft.aspnetcore.identity.2.1.1.nupkg
Dependency Hierarchy:
Found in HEAD commit: b984cd05e6d24e7f9d2e92ad8183e9a4a732743c
Found in base branch: master
Vulnerability Details
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2.
Publish Date: 2018-07-11
URL: CVE-2018-8171
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-vhvh-528q-ff3p
Release Date: 2018-07-11
Fix Resolution: Microsoft.AspNetCore.Identity - 1.0.6,1.1.6,2.0.4,2.1.2
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: