### Impact When the proof key recovered from the RSTR can be observed by a party that is not the legitimate client, that party can impersonate the authenticated Windows principal for the lifetime of the SCT (default ~10 hours) and decrypt or forge any subsequent WS‑SecureConversation traffic that uses keys derived from the SCT. #### Preconditions Using security mode TransportWithMessageCredential with client credential type Windows, along with session establishment (which triggers use of WS-SecureConversation). ### Patches Fixed in CoreWCF v1.9.1 ### Workarounds Ensure communication is protected by SSL/TLS to prevent capturing of SCT negotiation handshake.
Update CoreWCF.Primitives to 1.9.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality affects CoreWCF.Primitives (nuget). Severity is high. ### Impact When the proof key recovered from the RSTR can be observed by a party that is not the legitimate client, that party can impersonate the authenticated Windows principal for the lifetime of the SCT (default ~10 hours) and decrypt or forge any subsequent WS‑SecureConversation traffic that uses keys derived from the SCT. #### Preconditions Using security mode TransportWithMessageCredential with client credential type Windows, along with session establishment (which triggers use of WS-SecureConversation). ### Patches Fixed in CoreWCF v1.9.1 ### Workarounds Ensure communication is protected by SSL/TLS to prevent capturing of SCT negotiation handshake.
AI coding agents often install or upgrade packages automatically in nuget. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| CoreWCF.Primitives |
### Impact When the proof key recovered from the RSTR can be observed by a party that is not the legitimate client, that party can impersonate the authenticated Windows principal for the lifetime of the SCT (default ~10 hours) and decrypt or forge any subsequent WS‑SecureConversation traffic that uses keys derived from the SCT. #### Preconditions Using security mode TransportWithMessageCredential with client credential type Windows, along with session establishment (which triggers use of WS-SecureConversation). ### Patches Fixed in CoreWCF v1.9.1 ### Workarounds Ensure communication is protected by SSL/TLS to prevent capturing of SCT negotiation handshake.
Update CoreWCF.Primitives to 1.9.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality affects CoreWCF.Primitives (nuget). Severity is high. ### Impact When the proof key recovered from the RSTR can be observed by a party that is not the legitimate client, that party can impersonate the authenticated Windows principal for the lifetime of the SCT (default ~10 hours) and decrypt or forge any subsequent WS‑SecureConversation traffic that uses keys derived from the SCT. #### Preconditions Using security mode TransportWithMessageCredential with client credential type Windows, along with session establishment (which triggers use of WS-SecureConversation). ### Patches Fixed in CoreWCF v1.9.1 ### Workarounds Ensure communication is protected by SSL/TLS to prevent capturing of SCT negotiation handshake.
AI coding agents often install or upgrade packages automatically in nuget. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| CoreWCF.Primitives |
| >=1.9.0,<1.9.1 |
| 1.9.1 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| >=1.9.0,<1.9.1 |
| 1.9.1 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard