{"id":15659,"date":"2023-01-23T09:08:12","date_gmt":"2023-01-23T09:08:12","guid":{"rendered":"https:\/\/scrum-masters.cornerd.com\/?p=15659"},"modified":"2023-01-23T09:09:12","modified_gmt":"2023-01-23T09:09:12","slug":"kentor-authservices-0-21-2-security-release-passion-for-coding","status":"publish","type":"post","link":"https:\/\/cornerd.com\/kentor-authservices-0-21-2-security-release-passion-for-coding\/","title":{"rendered":"Kentor.AuthServices 0.21.2 Security Release | Passion for Coding"},"content":{"rendered":"

<\/p>\n

\n
\n

\n <\/p>\n

Kentor.AuthServices 0.21.2 has simply been launched to NuGet. It is a safety launch fixing three points.<\/p>\n

    \n
  1. XML External Entity Injection (affecting .NET 4.5 solely)<\/li>\n
  2. Malicious IdP may cause write to arbitrary file<\/li>\n
  3. Flawed ReturnUrl validation results in Open Redirect<\/li>\n<\/ol>\n

    The first two points have been reported by John Heasman, Morgan Roman and Joshua Estalilla from DocuSign. While I’ve dreaded the day after I would get a safety problem I’m extraordinarily proud of the professionalism of the disclosure. I acquired the report privately, together with detailed descriptions, copy steps and strong suggestions on repair it. I’m very grateful you took the time to overview AuthServices and discover the problems and for the detailed reviews.<\/p>\n

    More particulars on the vulernabilities can be printed later.<\/p>\n