VDB
Sign up
HIGH7.4

GHSA-2288-8h3r-cqgg

CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality

Quick fix

GHSA-2288-8h3r-cqgg — CoreWCF.Primitives: upgrade to the fixed version with the command below.

dotnet add package CoreWCF.Primitives --version 1.9.1

Details

### Impact When the proof key recovered from the RSTR can be observed by a party that is not the legitimate client, that party can impersonate the authenticated Windows principal for the lifetime of the SCT (default ~10 hours) and decrypt or forge any subsequent WS‑SecureConversation traffic that uses keys derived from the SCT.

#### Preconditions Using security mode TransportWithMessageCredential with client credential type Windows, along with session establishment (which triggers use of WS-SecureConversation).

### Patches Fixed in CoreWCF v1.9.1

### Workarounds Ensure communication is protected by SSL/TLS to prevent capturing of SCT negotiation handshake.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/CoreWCF.Primitives
Introduced in: 1.9.0Fixed in: 1.9.1
Fixdotnet add package CoreWCF.Primitives --version 1.9.1

References