You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I apologize. Looking at the vulnerability, it looked like it was a very recent vulnerability. I should've looked further. Both issues have indeed been addressed. Thanks for notifying. This can be closed.
Issue
Microsoft.Data.SqlClient 5.1.1
usesAzure.Identity 1.7.0
which has a known HIGH vulnerability CVE-2023-36414.On top of that I'm surprised that it references
Azure.Identity
at all. Since this seems to me a higher order concern than sec the SqlClient.To reproduce
Get a clean project and add a dependency to
Microsoft.Data.SqlClient 5.1.1
Run de following command in powershell
Further technical details
Microsoft.Data.SqlClient version: 5.1.1
.NET target: .NET 7
SQL Server version: NA
Operating system: Windows 11
The text was updated successfully, but these errors were encountered: