CVE-2018-8292
CVE-2018-8292 is a high-severity vulnerability in Microsoft Asp.net Core with a CVSS 3.x base score of 7.5. Its EPSS exploit-prediction score of 15% places it in the 97th percentile, indicating an elevated likelihood of exploitation. The underlying weakness is classified as CWE-200.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- CVSS v2: 5.0
- EPSS exploit prediction: 15% (97th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-200
- Affected product: Microsoft Asp.net Core
- Published:
- Last modified:
Description
An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0.
Frequently asked questions
- What is CVE-2018-8292?
- An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0.
- How severe is CVE-2018-8292?
- CVE-2018-8292 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2018-8292 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 15% (97th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2018-8292?
- CVE-2018-8292 primarily affects Microsoft Asp.net Core. In total, 4 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2018-8292?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2018-8292 published?
- CVE-2018-8292 was published on 2018-10-10 and last updated on 2026-06-17.
References
- http://www.securityfocus.com/bid/105548
- https://access.redhat.com/errata/RHSA-2018:2902
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8292
Affected products (4)
- cpe:2.3:a:microsoft:asp.net_core:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:asp.net_core:1.1:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:asp.net_core:2.1:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:powershell_core:6.0:*:*:*:*:*:*:*
More vulnerabilities in Microsoft Asp.net Core
- CVE-2025-55315 — Critical (CVSS 9.9): Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized…
- CVE-2026-40372 — Critical (CVSS 9.1): Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges…
- CVE-2021-43877 — High (CVSS 8.8): ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability
- CVE-2020-0603 — High (CVSS 8.8): A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in…
- CVE-2019-1302 — High (CVSS 8.8): An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project…
- CVE-2018-0787 — High (CVSS 8.8): ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how web applications that are…
All CVEs affecting Microsoft Asp.net Core →
Other CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) vulnerabilities
- CVE-2026-92960 — Critical (CVSS 10.0): vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing…
- CVE-2026-92947 — Critical (CVSS 10.0): vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by…
- CVE-2026-70478 — Critical (CVSS 10.0): Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST…
- CVE-2026-27604 — Critical (CVSS 10.0): FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version…
- CVE-2026-40965 — Critical (CVSS 10.0): Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a…
- CVE-2026-42826 — Critical (CVSS 10.0): Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose…
Browse all CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) vulnerabilities →