GHSA-vhvh-528q-ff3p
Dashboard / Vulnerabilities / GHSA-vhvh-528q-ff3p
Summary: Security feature bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated
Details: A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-8171, https://github.com/advisories/GHSA-vhvh-528q-ff3p, https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8171, http://www.securityfocus.com/bid/104659, http://www.securitytracker.com/id/1041267
Affected packages
Package
Name: Microsoft.AspNetCore.Identity
Purl: pkg:nuget/Microsoft.AspNetCore.Identity
Affected ranges
Type: ECOSYSTEM
Events:
