Bug 1533725 (CVE-2018-0786) - CVE-2018-0786 ASP.NET: Incorrect certificate validation can allow attackers to bypass security checks
Summary: CVE-2018-0786 ASP.NET: Incorrect certificate validation can allow attackers t...
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2018-0786
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1545986 1545987 1545988
Blocks: 1533726
TreeView+ depends on / blocked
 
Reported: 2018-01-12 04:16 UTC by Sam Fowler
Modified: 2019-09-29 14:29 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2018-03-19 03:12:58 UTC
Embargoed:


Attachments (Terms of Use)

Description Sam Fowler 2018-01-12 04:16:51 UTC
.NET Core 1.0, 1.1 and 2.0 do not correctly validate X509 certificates and can allow an attacker to bypass security checks by presenting an invalid certificate marked for a specific use.


References:
https://nvd.nist.gov/vuln/detail/CVE-2018-0786
https://github.com/dotnet/announcements/issues/51

Comment 2 Trevor Jay 2018-03-19 03:12:58 UTC
Changed the affects, this is an ASP.Net issue only.


Note You need to log in before you can comment on or make changes to this bug.