GHSA-6jj2-4q5c-x8g6
CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance
Quick fix
GHSA-6jj2-4q5c-x8g6 — CoreWCF.NetNamedPipe: upgrade to the fixed version with the command below.
dotnet add package CoreWCF.NetNamedPipe --version 1.8.1Details
### Impact CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance, allowing local interception of NetNamedPipe traffic. NetNamedPipe creates a shared memory object based on the listening url, then generated a unique GUID for the named pipe it will be using and saves this to the shared memory object. Then it creates the named pipe to listen for clients. This requires an attacker to race the service and create the named pipe between the service publishing the GUID to the shared memory location (which the attacker needs to read) and the service creating the named pipe itself.
### Patches Fixed in CoreWCF v1.8.1 and v1.9.1
### Workarounds None
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.8.1dotnet add package CoreWCF.NetNamedPipe --version 1.8.11.9.0Fixed in: 1.9.1dotnet add package CoreWCF.NetNamedPipe --version 1.9.1