VDB
Sign up
HIGH7.5

GHSA-jc8g-xhw5-6x46

Improper Certificate Validation in Microsoft .NET Framework components

Quick fix

GHSA-jc8g-xhw5-6x46 — Microsoft.NETCore.UniversalWindowsPlatform: upgrade to the fixed version with the command below.

dotnet add package Microsoft.NETCore.UniversalWindowsPlatform --version 5.2.4

Details

Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulnerability due to the way certificates are validated, aka ".NET Security Feature Bypass Vulnerability."

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/Microsoft.NETCore.UniversalWindowsPlatform
Introduced in: 5.2.0Fixed in: 5.2.4
Fixdotnet add package Microsoft.NETCore.UniversalWindowsPlatform --version 5.2.4
NuGet/Microsoft.NETCore.UniversalWindowsPlatform
Introduced in: 5.3.0Fixed in: 5.3.5
Fixdotnet add package Microsoft.NETCore.UniversalWindowsPlatform --version 5.3.5
NuGet/Microsoft.NETCore.UniversalWindowsPlatform
Introduced in: 5.4.0Fixed in: 5.4.2
Fixdotnet add package Microsoft.NETCore.UniversalWindowsPlatform --version 5.4.2
NuGet/Microsoft.NETCore.UniversalWindowsPlatform
Introduced in: 6.0.0Fixed in: 6.0.6
Fixdotnet add package Microsoft.NETCore.UniversalWindowsPlatform --version 6.0.6
NuGet/System.ServiceModel.Primitives
Introduced in: 4.4.0Fixed in: 4.4.1
Fixdotnet add package System.ServiceModel.Primitives --version 4.4.1
NuGet/System.ServiceModel.Primitives
Introduced in: 4.3.0Fixed in: 4.3.1
Fixdotnet add package System.ServiceModel.Primitives --version 4.3.1
NuGet/System.ServiceModel.Primitives
Introduced in: 4.1.0Fixed in: 4.1.1
Fixdotnet add package System.ServiceModel.Primitives --version 4.1.1
NuGet/System.ServiceModel.Http
Introduced in: 4.4.0Fixed in: 4.4.1
Fixdotnet add package System.ServiceModel.Http --version 4.4.1
NuGet/System.ServiceModel.Http
Introduced in: 4.3.0Fixed in: 4.3.1
Fixdotnet add package System.ServiceModel.Http --version 4.3.1
NuGet/System.ServiceModel.Http
Introduced in: 4.1.0Fixed in: 4.1.1
Fixdotnet add package System.ServiceModel.Http --version 4.1.1
NuGet/System.ServiceModel.NetTcp
Introduced in: 4.4.0Fixed in: 4.4.1
Fixdotnet add package System.ServiceModel.NetTcp --version 4.4.1
NuGet/System.ServiceModel.NetTcp
Introduced in: 4.3.0Fixed in: 4.3.1
Fixdotnet add package System.ServiceModel.NetTcp --version 4.3.1
NuGet/System.ServiceModel.NetTcp
Introduced in: 4.1.0Fixed in: 4.1.1
Fixdotnet add package System.ServiceModel.NetTcp --version 4.1.1
NuGet/System.ServiceModel.Duplex
Introduced in: 4.4.0Fixed in: 4.4.1
Fixdotnet add package System.ServiceModel.Duplex --version 4.4.1
NuGet/System.ServiceModel.Duplex
Introduced in: 4.3.0Fixed in: 4.3.1
Fixdotnet add package System.ServiceModel.Duplex --version 4.3.1
NuGet/System.ServiceModel.Duplex
Introduced in: 4.0.1Fixed in: 4.0.2
Fixdotnet add package System.ServiceModel.Duplex --version 4.0.2
NuGet/System.ServiceModel.Security
Introduced in: 4.4.0Fixed in: 4.4.1
Fixdotnet add package System.ServiceModel.Security --version 4.4.1
NuGet/System.ServiceModel.Security
Introduced in: 4.3.0Fixed in: 4.3.1
Fixdotnet add package System.ServiceModel.Security --version 4.3.1
NuGet/System.ServiceModel.Security
Introduced in: 4.0.1Fixed in: 4.0.2
Fixdotnet add package System.ServiceModel.Security --version 4.0.2
NuGet/System.Private.ServiceModel
Introduced in: 4.4.0Fixed in: 4.4.1
Fixdotnet add package System.Private.ServiceModel --version 4.4.1
NuGet/System.Private.ServiceModel
Introduced in: 4.3.0Fixed in: 4.3.1
Fixdotnet add package System.Private.ServiceModel --version 4.3.1
NuGet/System.Private.ServiceModel
Introduced in: 4.1.0Fixed in: 4.1.1
Fixdotnet add package System.Private.ServiceModel --version 4.1.1

References