Описание
Improper Certificate Validation in Microsoft .NET Framework components
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulnerability due to the way certificates are validated, aka ".NET Security Feature Bypass Vulnerability."
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2018-0786
- https://github.com/dotnet/announcements/issues/51
- https://github.com/github/advisory-database/issues/302
- https://github.com/advisories/GHSA-jc8g-xhw5-6x46
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0786
- https://www.nuget.org/packages/System.ServiceModel.Duplex#versions-body-tab
Пакеты
Microsoft.NETCore.UniversalWindowsPlatform
>= 5.2.0, < 5.2.4
5.2.4
Microsoft.NETCore.UniversalWindowsPlatform
>= 5.3.0, < 5.3.5
5.3.5
Microsoft.NETCore.UniversalWindowsPlatform
>= 5.4.0, < 5.4.2
5.4.2
Microsoft.NETCore.UniversalWindowsPlatform
>= 6.0.0, < 6.0.6
6.0.6
System.ServiceModel.Primitives
= 4.4.0
4.4.1
System.ServiceModel.Primitives
= 4.3.0
4.3.1
System.ServiceModel.Primitives
= 4.1.0
4.1.1
System.ServiceModel.Http
= 4.4.0
4.4.1
System.ServiceModel.Http
= 4.3.0
4.3.1
System.ServiceModel.Http
= 4.1.0
4.1.1
System.ServiceModel.NetTcp
= 4.4.0
4.4.1
System.ServiceModel.NetTcp
= 4.3.0
4.3.1
System.ServiceModel.NetTcp
= 4.1.0
4.1.1
System.ServiceModel.Duplex
= 4.4.0
4.4.1
System.ServiceModel.Duplex
= 4.3.0
4.3.1
System.ServiceModel.Duplex
= 4.0.1
4.0.2
System.ServiceModel.Security
= 4.4.0
4.4.1
System.ServiceModel.Security
= 4.3.0
4.3.1
System.ServiceModel.Security
= 4.0.1
4.0.2
System.Private.ServiceModel
= 4.4.0
4.4.1
System.Private.ServiceModel
= 4.3.0
4.3.1
System.Private.ServiceModel
= 4.1.0
4.1.1
Связанные уязвимости
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulnerability due to the way certificates are validated, aka ".NET Security Feature Bypass Vulnerability."
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulnerability due to the way certificates are validated, aka ".NET Security Feature Bypass Vulnerability."