dotnet / dotnet/wcf

CVE-2023-29331 - System.ServiceModel.Primitives6.2.0 - upgrade - System.Security.Cryptography.Xml6.0.1 to System.Security.Cryptography.Xml 8.0.1

Open
#5,611 5 comments 2 reactions 0 assignees View on GitHub
triaged
Dominant language
C#
Stars
1.8k
Forks
576
Avg merge
6d 9h
Merged PRs (30d)
2

Description

**Describe the bug**
CVE-2023-29331 is related to System.ServiceModel.Primitives6.2.0 in the following manner
nuget: System.ServiceModel.Primitives/6.2.0
refers - nuget: System.Security.Cryptography.Xml/6.0.1
refers - nuget: System.Security.Cryptography.Pkcs/6.0.1

![image](https://github.com/user-attachments/assets/288877e4-c13f-4e40-94ee-a0a5a032e56f)

https://github.com/dotnet/announcements/issues/257

![image](https://github.com/user-attachments/assets/e8733fb5-9df0-4ab1-a9e4-eb1ed7a562ef)

CVE-2023-29331 - refers - nuget: System.Security.Cryptography.Pkcs/6.0.1

upgrade - System.Security.Cryptography.Xml6.0.1 to System.Security.Cryptography.Xml 8.0.1

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.