OSV 1.4.0 · github-reviewed · 修改于 2026-06-20 04:47
发布时间
2026-06-20 04:47
GitHub 审查时间
2026-06-20 04:47
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/06/GHSA-2288-8h3r-cqgg/GHSA-2288-8h3r-cqgg.json
When the proof key recovered from the RSTR can be observed by a party that is not the legitimate client, that party can impersonate the authenticated Windows principal for the lifetime of the SCT (default ~10 hours) and decrypt or forge any subsequent WS‑SecureConversation traffic that uses keys derived from the SCT.
Using security mode TransportWithMessageCredential with client credential type Windows, along with session establishment (which triggers use of WS-SecureConversation).
Fixed in CoreWCF v1.9.1
Ensure communication is protected by SSL/TLS to prevent capturing of SCT negotiation handshake.