Описание
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does not correctly resolve the issuer signing key or require signed tokens when IdentityConfiguration is used with federated bindings, allowing an unauthenticated remote attacker to impersonate any principal the trusted STS could issue. This issue is fixed in versions 1.8.1 and 1.9.1.
Ссылки
EPSS
Процентиль: 16%
0.00246
Низкий
10 Critical
CVSS3
Дефекты
CWE-290
Связанные уязвимости
CVSS3: 10
github
около 2 месяцев назад
CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation
EPSS
Процентиль: 16%
0.00246
Низкий
10 Critical
CVSS3
Дефекты
CWE-290