.NET Core 1.0, 1.1 and 2.0 do not correctly validate X509 certificates and can allow an attacker to bypass security checks by presenting an invalid certificate marked for a specific use. References: https://nvd.nist.gov/vuln/detail/CVE-2018-0786 https://github.com/dotnet/announcements/issues/51
Changed the affects, this is an ASP.Net issue only.