Related Vulnerabilities: CVE-2021-31204  

An elevation of privilege vulnerability exists in .NET 5.0 and .NET Core 3.1 when a user runs a single file application on Operating Systems based on Linux or macOS. The issue is fixed in .NET 5.0, Runtime 5.0.6 and SDK 5.0.203, as well as .NET Core 3.1, Runtime 3.1.15 and SDK 3.1.115.

Severity Medium

Remote No

Type Privilege escalation

Description

An elevation of privilege vulnerability exists in .NET 5.0 and .NET Core 3.1 when a user runs a single file application on Operating Systems based on Linux or macOS. The issue is fixed in .NET 5.0, Runtime 5.0.6 and SDK 5.0.203, as well as .NET Core 3.1, Runtime 3.1.15 and SDK 3.1.115.

AVG-1945 dotnet-runtime-3.1, dotnet-sdk-3.1 3.1.14.sdk114-1 Medium Vulnerable

AVG-1944 dotnet-runtime, dotnet-sdk 5.0.5.sdk202-1 Medium Vulnerable

https://github.com/dotnet/announcements/issues/185