{"id":"CVE-2018-8292","details":"An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka \".NET Core Information Disclosure Vulnerability.\" This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0.","aliases":["GHSA-7jgj-8wvc-jh57"],"modified":"2026-08-18T11:19:56.774307Z","published":"2018-10-10T13:29:01.213Z","references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/105548"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:2902"},{"type":"FIX","url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8292"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dotnet/aspnetcore","events":[{"introduced":"93ef04d69d1f1a189e9c342f656e85af50a14bb6"},{"last_affected":"00e08d8c11f4e9649492342c9c613a758efd2e4d"}],"database_specific":{"cpe":["cpe:2.3:a:microsoft:asp.net_core:1.0:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:asp.net_core:1.1:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:asp.net_core:2.1:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.0"},{"last_affected":"1.0"},{"introduced":"1.1"},{"last_affected":"1.1"},{"introduced":"2.1"},{"last_affected":"2.1"}],"source":"CPE_STRING"}}],"versions":["1.0","1.1","2.1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-8292.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/powershell/powershell","events":[{"introduced":"2f818615bed15141c062dd185f659ed110d9c6ba"},{"last_affected":"2f818615bed15141c062dd185f659ed110d9c6ba"}],"database_specific":{"cpe":"cpe:2.3:a:microsoft:powershell_core:6.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"6.0"},{"last_affected":"6.0"}],"source":"CPE_STRING"}}],"versions":["6.0","v6.0.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-8292.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}