Loading HuntDB...

GHSA-p9wx-v264-q34p

GitHub Security Advisory

Improper Certificate Validation in Microsoft .NET Framework components

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework Security Feature Bypass Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, ASP.NET Core 1.1, Microsoft .NET Framework 4.5.2, ASP.NET Core 2.0, ASP.NET Core 1.0, .NET Core 1.1, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 1.0, .NET Core 2.0, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2.

Affected Packages

NuGet System.Private.ServiceModel
Affected versions: 4.0.0 (fixed in 4.1.3)
NuGet System.Private.ServiceModel
Affected versions: 4.3.0 (fixed in 4.3.3)
NuGet System.Private.ServiceModel
Affected versions: 4.4.0 (fixed in 4.4.4)
NuGet System.Private.ServiceModel
Affected versions: 4.5.0 (fixed in 4.5.3)
NuGet System.ServiceModel.Duplex
Affected versions: 4.3.0 (fixed in 4.3.3)
NuGet System.ServiceModel.Duplex
Affected versions: 4.4.0 (fixed in 4.4.4)
NuGet System.ServiceModel.Duplex
Affected versions: 4.5.0 (fixed in 4.5.3)
NuGet System.ServiceModel.Duplex
Affected versions: 4.0.0 (fixed in 4.0.4)
NuGet System.ServiceModel.Http
Affected versions: 4.3.0 (fixed in 4.3.3)
NuGet System.ServiceModel.Http
Affected versions: 4.4.0 (fixed in 4.4.4)
NuGet System.ServiceModel.Http
Affected versions: 4.5.0 (fixed in 4.5.3)
NuGet System.ServiceModel.Http
Affected versions: 4.0.0 (fixed in 4.1.3)
NuGet System.ServiceModel.NetTcp
Affected versions: 4.3.0 (fixed in 4.3.3)
NuGet System.ServiceModel.NetTcp
Affected versions: 4.4.0 (fixed in 4.4.4)
NuGet System.ServiceModel.NetTcp
Affected versions: 4.5.0 (fixed in 4.5.3)
NuGet System.ServiceModel.NetTcp
Affected versions: 4.0.0 (fixed in 4.1.3)
NuGet System.ServiceModel.Primitives
Affected versions: 4.3.0 (fixed in 4.3.3)
NuGet System.ServiceModel.Primitives
Affected versions: 4.4.0 (fixed in 4.4.4)
NuGet System.ServiceModel.Primitives
Affected versions: 4.5.0 (fixed in 4.5.3)
NuGet System.ServiceModel.Primitives
Affected versions: 4.0.0 (fixed in 4.1.3)
NuGet System.ServiceModel.Security
Affected versions: 4.3.0 (fixed in 4.3.3)
NuGet System.ServiceModel.Security
Affected versions: 4.4.0 (fixed in 4.4.4)
NuGet System.ServiceModel.Security
Affected versions: 4.5.0 (fixed in 4.5.3)
NuGet System.ServiceModel.Security
Affected versions: 4.0.0 (fixed in 4.0.4)

Related CVEs

Key Information

GHSA ID
GHSA-p9wx-v264-q34p
Published
May 14, 2022 3:00 AM
Last Modified
July 8, 2022 7:23 PM
CVSS Score
5.0 /10
Primary Ecosystem
NuGet
Primary Package
System.Private.ServiceModel
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 28, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.