CVE-2018-8292: Microsoft ASP.NET Core

High severity, CVSS 7.5. EPSS: 14.8% chance of exploitation in the next 30 days.

An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0.

Affected products

  • Microsoft ASP.NET Core: version 1.0 only; version 1.1 only; version 2.1 only
  • Microsoft PowerShell Core: version 6.0 only

Published 2018-10-10. Last modified 2026-06-17.