Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Azure.Identity version used has a high vulnerability #2241

Closed
thompson-tomo opened this issue Nov 24, 2023 · 1 comment
Closed

Azure.Identity version used has a high vulnerability #2241

thompson-tomo opened this issue Nov 24, 2023 · 1 comment
Labels
2️⃣ Duplicate Issue/PR that is a duplicate and already exists.

Comments

@thompson-tomo
Copy link

Describe the bug

All versions of the library are using a version of Azure.Identity which has an identified vulnerability which has been fixed in newer version of the library

To reproduce

Open nuget package manager with library installed
Look at vulnerabilities of transitive packages and observe warning about vulnerability for Azure.Identity
Look at dependencies of Microsoft.Data.SqlClient and observe this is the source of the vulnerable library

Expected behavior

Azure.Identity version increased to 1.10.2+

Further technical details

GHSA-5mfx-4wcx-rv27

@JRahnama JRahnama added the 2️⃣ Duplicate Issue/PR that is a duplicate and already exists. label Nov 25, 2023
@JRahnama
Copy link
Contributor

Duplicate of #2195

@JRahnama JRahnama marked this as a duplicate of #2195 Nov 25, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
2️⃣ Duplicate Issue/PR that is a duplicate and already exists.
Projects
None yet
Development

No branches or pull requests

2 participants