CVE-2017-8700: Microsoft ASP.NET Core
High severity, CVSS 7.5. EPSS: 10.5% chance of exploitation in the next 30 days.
ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normally restricted content from a web application, aka "ASP.NET Core Information Disclosure Vulnerability".
Affected products
- Microsoft ASP.NET Core: version 1.0 only; version 1.1 only; version 2.0 only
Published 2017-11-15. Last modified 2026-06-17.