-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
system.data.sqlclient.4.8.4.nupkg: 2 vulnerabilities (highest severity is: 8.7) #29
Comments
✔️ This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory. |
ℹ️ This issue was automatically re-opened by Mend because the vulnerable library in the specific branch(es) has been detected in the Mend inventory. |
✔️ This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory. |
ℹ️ This issue was automatically re-opened by Mend because the vulnerable library in the specific branch(es) has been detected in the Mend inventory. |
Provides the data provider for SQL Server. These classes provide access to versions of SQL Server and encapsulate database-specific protocols, including tabular data stream (TDS)
Commonly Used Types:
System.Data.SqlClient.SqlConnection
System.Data.SqlClient.SqlException
System.Data.SqlClient.SqlParameter
System.Data.SqlDbType
System.Data.SqlClient.SqlDataReader
System.Data.SqlClient.SqlCommand
System.Data.SqlClient.SqlTransaction
System.Data.SqlClient.SqlParameterCollection
System.Data.SqlClient.SqlClientFactory
When using NuGet 3.x this package requires at least version 3.4.
Library home page: https://api.nuget.org/packages/system.data.sqlclient.4.8.4.nupkg
Path to dependency file: /TheWheel.ETL.Parlot/TheWheel.ETL.Parlot.csproj
Path to vulnerable library: /home/wss-scanner/.nuget/packages/system.data.sqlclient/4.8.4/system.data.sqlclient.4.8.4.nupkg
Found in HEAD commit: 4523a90c162a002998acd7d6510bd4bdea60b7e9
Vulnerabilities
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Vulnerable Library - system.data.sqlclient.4.8.4.nupkg
Provides the data provider for SQL Server. These classes provide access to versions of SQL Server and encapsulate database-specific protocols, including tabular data stream (TDS)
Commonly Used Types:
System.Data.SqlClient.SqlConnection
System.Data.SqlClient.SqlException
System.Data.SqlClient.SqlParameter
System.Data.SqlDbType
System.Data.SqlClient.SqlDataReader
System.Data.SqlClient.SqlCommand
System.Data.SqlClient.SqlTransaction
System.Data.SqlClient.SqlParameterCollection
System.Data.SqlClient.SqlClientFactory
When using NuGet 3.x this package requires at least version 3.4.
Library home page: https://api.nuget.org/packages/system.data.sqlclient.4.8.4.nupkg
Path to dependency file: /TheWheel.ETL.Parlot/TheWheel.ETL.Parlot.csproj
Path to vulnerable library: /home/wss-scanner/.nuget/packages/system.data.sqlclient/4.8.4/system.data.sqlclient.4.8.4.nupkg
Dependency Hierarchy:
Found in HEAD commit: 4523a90c162a002998acd7d6510bd4bdea60b7e9
Found in base branch: main
Vulnerability Details
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
Publish Date: 2024-01-09
URL: CVE-2024-0056
CVSS 3 Score Details (8.7)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-98g6-xh36-x2p7
Release Date: 2024-01-09
Fix Resolution: Microsoft.Data.SqlClient - 2.1.7,3.1.5,4.0.5,5.1.3, System.Data.SqlClient - 4.8.6
Step up your Open Source Security Game with Mend here
Vulnerable Library - system.data.sqlclient.4.8.4.nupkg
Provides the data provider for SQL Server. These classes provide access to versions of SQL Server and encapsulate database-specific protocols, including tabular data stream (TDS)
Commonly Used Types:
System.Data.SqlClient.SqlConnection
System.Data.SqlClient.SqlException
System.Data.SqlClient.SqlParameter
System.Data.SqlDbType
System.Data.SqlClient.SqlDataReader
System.Data.SqlClient.SqlCommand
System.Data.SqlClient.SqlTransaction
System.Data.SqlClient.SqlParameterCollection
System.Data.SqlClient.SqlClientFactory
When using NuGet 3.x this package requires at least version 3.4.
Library home page: https://api.nuget.org/packages/system.data.sqlclient.4.8.4.nupkg
Path to dependency file: /TheWheel.ETL.Parlot/TheWheel.ETL.Parlot.csproj
Path to vulnerable library: /home/wss-scanner/.nuget/packages/system.data.sqlclient/4.8.4/system.data.sqlclient.4.8.4.nupkg
Dependency Hierarchy:
Found in HEAD commit: 4523a90c162a002998acd7d6510bd4bdea60b7e9
Found in base branch: main
Vulnerability Details
.NET Framework Information Disclosure Vulnerability
Mend Note: Converted from WS-2022-0377, on 2022-11-10.
Publish Date: 2022-11-09
URL: CVE-2022-41064
CVSS 3 Score Details (5.8)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-8g2p-5pqh-5jmc
Release Date: 2022-11-09
Fix Resolution: Microsoft.Data.SqlClient - 1.1.4,2.1.2;System.Data.SqlClient - 4.8.5
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: