Access Restriction Bypass Affecting microsoft.aspnetcore.app.runtime.win-arm package, versions [,6.0.20) [7.0.0,7.0.9)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.Test your applications
- Snyk ID SNYK-DOTNET-MICROSOFTASPNETCOREAPPRUNTIMEWINARM-5772978
- published 12 Jul 2023
- disclosed 11 Jul 2023
- credit Ethan McKee Harris, Matt Cotterell, Jack Moran
How to fix?
Microsoft.AspNetCore.App.Runtime.win-arm to version 6.0.20, 7.0.9 or higher.
Microsoft.AspNetCore.App.Runtime.win-arm is a package providing a default set of APIs for building an ASP.NET Core application. Contains assets used for self-contained deployments.
Affected versions of this package are vulnerable to Access Restriction Bypass. A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords.