CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 7.4epss 0.2%
probabilidade de exploração
0.2%top 93% das CVEs
exploração observada
nãonenhuma fonte reporta
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. In version 1.9.0, CoreWCF SPNEGO SecurityContextToken negotiation can expose the proof key recovered from the RSTR when TransportWithMessageCredential with Windows client credentials and session establishment are used, allowing an observer to impersonate the authenticated Windows principal and decrypt or forge WS-SecureConversation traffic. This issue is fixed in version 1.9.1.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Produtos afetados
CoreWCF · CoreWCFReferências
https://github.com/CoreWCF/CoreWCF/commit/2afae08b2fa5288428df89e8161116b816cf6b4bhttps://github.com/CoreWCF/CoreWCF/commit/f216aa6929d41dc99cee098b1e69c260ec4c41c7https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-2288-8h3r-cqgg