Vulnerability CVE-2021-31204: Information

Description

.NET and Visual Studio Elevation of Privilege Vulnerability

Severity: HIGH (7.3) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Published: May 11, 2021
Modified: Dec. 29, 2023

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
dotnet-bootstrap-3.1p103.1.16-alt13.1.32-alt1ALT-PU-2021-2098-1276447Fixed
dotnet-bootstrap-3.1p93.1.22-alt13.1.22-alt1ALT-PU-2022-1548-1295274Fixed
dotnet-bootstrap-3.1c10f13.1.16-alt13.1.32-alt1ALT-PU-2021-2098-1276447Fixed
dotnet-bootstrap-5.0p105.0.7-alt15.0.17-alt1ALT-PU-2021-2109-1276449Fixed
dotnet-bootstrap-5.0p95.0.14-alt15.0.14-alt1ALT-PU-2022-1544-1295274Fixed
dotnet-bootstrap-5.0c10f15.0.7-alt15.0.17-alt1ALT-PU-2021-2109-1276449Fixed
dotnet-coreclr-3.1p103.1.16-alt13.1.32-alt1ALT-PU-2021-2099-1276447Fixed
dotnet-coreclr-3.1p93.1.22-alt13.1.22-alt1ALT-PU-2022-1549-1295274Fixed
dotnet-coreclr-3.1c10f13.1.16-alt13.1.32-alt1ALT-PU-2021-2099-1276447Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:*
      Start including
      16.8.0
      End excliding
      16.9.5

      cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:*
      Start including
      16.5.0
      End excliding
      16.7.15

      cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:*
      Start including
      16.0
      End excliding
      16.4.22

      cpe:2.3:a:microsoft:visual_studio_2019:8.9:*:*:*:*:macos:*:*

      cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
      Start including
      5.0
      End including
      5.0.5

      cpe:2.3:a:microsoft:.net_core:*:*:*:*:*:*:*:*
      Start including
      3.1
      End including
      3.1.14

      Configuration 2

      cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*