Microsoft.AspNetCore.DataProtection is vulnerable to Improper Verification of Cryptographic Signature
91
Critical Risk
A bug in Microsoft.AspNetCore.DataProtection 10.0.0-10.0.6 NuGet packages can give an attacker the opportunity to execute an Elevation of Privilege attack by forging authentication cookies, and also allows some protected payloads to be decrypted. If an attacker used forged payloads to authenticate as a privileged user during the vulnerable window, they may have induced the application to issue legitimately-signed tokens (session refresh, API key, password reset link, etc.) to themselves. Those tokens remain valid after upgrading to 10.0.7 unless the DataProtection key ring is rotated.
You are affected if you are using a version that falls within the vulnerable range.
Microsoft.AspNetCore.DataProtection is vulnerable to Improper Verification of Cryptographic Signature in versions 10.0.0 - 10.0.6.
Upgrade the Microsoft.AspNetCore.DataProtection library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant