Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update to Microsoft.Data.SqlClient 5.1.5 to address CVE-2024-21319 #520

Closed
miksh7 opened this issue Feb 8, 2024 · 2 comments
Closed

Update to Microsoft.Data.SqlClient 5.1.5 to address CVE-2024-21319 #520

miksh7 opened this issue Feb 8, 2024 · 2 comments

Comments

@miksh7
Copy link

miksh7 commented Feb 8, 2024

Please update to Microsoft.Data.SqlClient 5.1.5 to address CVE-2024-21319

@ckadluba
Copy link
Member

ckadluba commented Feb 9, 2024

Hi @miksh7 and thank you for reporting your finding.

This issue is a duplicate of #517 which is already fixed in PR #518.

I should mention that the fix is yet only released in a prerelease on nuget.org. I will create a regular release within the next days and will leave this issue open until then for informational purposes.

@ckadluba
Copy link
Member

Release 6.5.2 is now on nuget with a fix https://www.nuget.org/packages/Serilog.Sinks.MSSqlServer/6.5.2.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants