NuGet package
microsoft.identitymodel.protocols.signedhttprequest
pkg:nuget/microsoft.identitymodel.protocols.signedhttprequest
Vulnerabilities (1)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-21643 | Hig | 7.1 | < 6.34.0 | 6.34.0 | Jan 10, 2024 | IdentityModel Extensions for .NET provide assemblies for web developers that wish to use federated identity providers for establishing the caller's identity. Anyone leveraging the `SignedHttpRequest`protocol or the `SignedHttpRequestValidator`is vulnerable. Microsoft.IdentityMode |
- affected < 6.34.0fixed 6.34.0
IdentityModel Extensions for .NET provide assemblies for web developers that wish to use federated identity providers for establishing the caller's identity. Anyone leveraging the `SignedHttpRequest`protocol or the `SignedHttpRequestValidator`is vulnerable. Microsoft.IdentityMode