SB2023112365 - Red Hat Enterprise Linux 8 update for dotnet7.0
Published: November 23, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2023-36049)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions in .NET, .NET Framework and Visual Studio, which leads to security restrictions bypass and privilege escalation.
2) Security features bypass (CVE-ID: CVE-2023-36558)
CWE-ID: CWE-254 - Security Features
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local attacker to compromise the target system.
The vulnerability exists due to security features bypass in ASP.NET Core. A local attacker can bypass validations on Blazor Server forms and gain access to sensitive information.
Remediation
Install update from vendor's website.