Red Hat Bugzilla – Bug 1636274
CVE-2018-8292 .NET Core: information disclosure due to authentication information exposed in a redirect
Last modified: 2018-10-10 11:24:48 EDT
A flaw was found in .NET Core. An information disclosure vulnerability in a redirect when authentication information has been added manually to an Authorization header. An attacker who successfully exploited this vulnerability could use the information to further compromise the web application.
This issue has been addressed in the following products: .NET Core on Red Hat Enterprise Linux Via RHSA-2018:2902 https://access.redhat.com/errata/RHSA-2018:2902