GHSA-xjr9-gg9q-jx3v
CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation
Quick fix
GHSA-xjr9-gg9q-jx3v — CoreWCF.Primitives: upgrade to the fixed version with the command below.
dotnet add package CoreWCF.Primitives --version 1.8.1Details
### Impact Full impersonation of any principal the trusted STS could have issued an assertion for — including administrative principals when the relying party grants them via SAML claims. Affects both SAML 1.1 and SAML 2.0.
#### Preconditions Relying-party service is hosted with WSFederationHttpBinding or WS2007FederationHttpBinding (or any binding that triggers FederatedSecurityTokenManager for issued-token validation), and IdentityConfiguration is wired (UseIdentityConfiguration = true). Attacker can reach the service over the network and knows the trusted STS’s public certificate (public certs are by design discoverable).
### Patches Fixed in CoreWCF v1.8.1 and v1.9.1
### Workarounds None
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.8.1dotnet add package CoreWCF.Primitives --version 1.8.11.9.0Fixed in: 1.9.1dotnet add package CoreWCF.Primitives --version 1.9.1