VDB
Sign up
CRITICAL10.0

GHSA-xjr9-gg9q-jx3v

CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation

Quick fix

GHSA-xjr9-gg9q-jx3v — CoreWCF.Primitives: upgrade to the fixed version with the command below.

dotnet add package CoreWCF.Primitives --version 1.8.1

Details

### Impact Full impersonation of any principal the trusted STS could have issued an assertion for — including administrative principals when the relying party grants them via SAML claims. Affects both SAML 1.1 and SAML 2.0.

#### Preconditions Relying-party service is hosted with WSFederationHttpBinding or WS2007FederationHttpBinding (or any binding that triggers FederatedSecurityTokenManager for issued-token validation), and IdentityConfiguration is wired (UseIdentityConfiguration = true). Attacker can reach the service over the network and knows the trusted STS’s public certificate (public certs are by design discoverable).

### Patches Fixed in CoreWCF v1.8.1 and v1.9.1

### Workarounds None

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/CoreWCF.Primitives
Introduced in: 0Fixed in: 1.8.1
Fixdotnet add package CoreWCF.Primitives --version 1.8.1
NuGet/CoreWCF.Primitives
Introduced in: 1.9.0Fixed in: 1.9.1
Fixdotnet add package CoreWCF.Primitives --version 1.9.1

References