Capgemini / Capgemini/powerapps-specflow-bindings

Vulnerability: Google.Protobuf-3.7.0.0.dll

Open
#121 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
C#
Stars
42
Forks
27
PR merge metrics
No merged PRs in 30d

Description

Vulnerability | Library | Description | Top Fix | Exists In Build Definitions
-- | -- | -- | -- | --
High7.5CVE-2021-22570Jan-26-2022 | Google.Protobuf-3.7.0.0.dll | Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater. | Upgrade to version Google.Protobuf - 3.15.0https://github.com/advisories/GHSA-77rm-9x9h-xj3g | Capgemini.PowerApps.SpecFlowBindings, Capgemini.PowerApps.SpecFlowBindings PR

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.