GHSA-rpj7-hr7h-w6p9
CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate
Quick fix
GHSA-rpj7-hr7h-w6p9 — CoreWCF.Primitives: upgrade to the fixed version with the command below.
dotnet add package CoreWCF.Primitives --version 1.8.1Details
### Impact When a service is configured to validate SAML tokens using a method other than X.509 certificate signing, the final signature verification is skipped.
#### Preconditions The service is configured to authenticate using SAML tokens and an out of band token resolver (commonly the IssuerTokenResolver of IssuedTokenServiceCredential) holds a non-X.509 SecurityToken whose key identifier the attacker can reference in the assertion’s `<KeyInfo>` - for example a `BinarySecretSecurityToken` representing the symmetric proof key issued by a WS-Trust symmetric-key holder-of-key STS.
### Patches Fixed in CoreWCF v1.8.1 and v1.9.1
### Workarounds None
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.8.1dotnet add package CoreWCF.Primitives --version 1.8.11.9.0Fixed in: 1.9.1dotnet add package CoreWCF.Primitives --version 1.9.1