QID 982537
QID 982537: Dotnet (nuget) Security Update for Wire (GHSA-hpw7-3vq3-mmv6)
Due to how Wire handles type information in its serialization format, malicious payloads can be passed to a deserializer. e.g. using a surrogate on the sender end, an attacker can pass information about a different type for the receiving end. And by doing so allowing the serializer to create any type on the deserializing end.
**This is the same issue that exists for .NET BinaryFormatter https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300?view=vs-2019**
This also applies to the fork of Wire, AkkaDotNet/Hyperion.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-hpw7-3vq3-mmv6 for updates pertaining to this vulnerability.
Vendor References
- GHSA-hpw7-3vq3-mmv6 -
github.com/advisories/GHSA-hpw7-3vq3-mmv6
CVEs related to QID 982537
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hpw7-3vq3-mmv6 | Wire |
|