CVE-2017-8700 was assigned to the following vulnerability: ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normally restricted content from a web application, aka "ASP.NET Core Information Disclosure Vulnerability". https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2017-8700
This issue did not affected .NET Core, but affected ASP.NET Core. More details can be found in the upstream Microsoft advisories: https://github.com/aspnet/Announcements/issues/279 https://github.com/aspnet/Mvc/issues/7054 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8700
External References: https://github.com/aspnet/Announcements/issues/279