Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-73vm-jqp4-fcg6

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communication Foundation (WCF) endpoint authentication in certain situations involving passwords over HTTPS, which allows remote attackers to bypass authentication by sending queries to an endpoint, aka "Authentication Bypass Vulnerability."

Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communication Foundation (WCF) endpoint authentication in certain situations involving passwords over HTTPS, which allows remote attackers to bypass authentication by sending queries to an endpoint, aka "Authentication Bypass Vulnerability."

EPSS

Процентиль: 96%
0.22765
Средний

Дефекты

CWE-287

Связанные уязвимости

nvd
больше 12 лет назад

Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communication Foundation (WCF) endpoint authentication in certain situations involving passwords over HTTPS, which allows remote attackers to bypass authentication by sending queries to an endpoint, aka "Authentication Bypass Vulnerability."

EPSS

Процентиль: 96%
0.22765
Средний

Дефекты

CWE-287