CVE-2024-50353 MEDIUM

CVE-2024-50353: ICG.AspNetCore.Utilities.CloudStorage's Secure Token Durations Different Than Expected

Vendor Iowacomputergurus
Product aspnetcore.utilities.cloudstorage
Weakness CWE-284
Published October 30, 2024
Last update October 30, 2024

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

ICG.AspNetCore.Utilities.CloudStorage is a collection of cloud storage utilities to assist with the management of files for cloud upload. Users of this library that set a duration for a SAS Uri with a value other than 1 hour may have generated a URL with a duration that is longer, or shorter than desired. Users not implemented SAS Uri's are unaffected. This issue was resolved in version 8.0.0 of the library.

Key dates

02Disclosure timeline

October 30, 2024 CVE published
October 30, 2024 Record updated