VDB
Sign up
HIGH7.4

GHSA-rpj7-hr7h-w6p9

CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate

Quick fix

GHSA-rpj7-hr7h-w6p9 — CoreWCF.Primitives: upgrade to the fixed version with the command below.

dotnet add package CoreWCF.Primitives --version 1.8.1

Details

### Impact When a service is configured to validate SAML tokens using a method other than X.509 certificate signing, the final signature verification is skipped.

#### Preconditions The service is configured to authenticate using SAML tokens and an out of band token resolver (commonly the IssuerTokenResolver of IssuedTokenServiceCredential) holds a non-X.509 SecurityToken whose key identifier the attacker can reference in the assertion’s `<KeyInfo>` - for example a `BinarySecretSecurityToken` representing the symmetric proof key issued by a WS-Trust symmetric-key holder-of-key STS.

### Patches Fixed in CoreWCF v1.8.1 and v1.9.1

### Workarounds None

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/CoreWCF.Primitives
Introduced in: 0Fixed in: 1.8.1
Fixdotnet add package CoreWCF.Primitives --version 1.8.1
NuGet/CoreWCF.Primitives
Introduced in: 1.9.0Fixed in: 1.9.1
Fixdotnet add package CoreWCF.Primitives --version 1.9.1

References