Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

System.Net.Requests new versions #1423

Open
p-brito opened this issue Jan 5, 2024 · 0 comments
Open

System.Net.Requests new versions #1423

p-brito opened this issue Jan 5, 2024 · 0 comments

Comments

@p-brito
Copy link

p-brito commented Jan 5, 2024

Hi,

I hope you can help me clarify a question about system packages.

Since version 4.3.0 no more versions were released for the package, if I understand correctly the package is now part of a bundle that is published in each dotnet version. Now, if we open the package Microsoft.NETCore.App.Ref we can see that the new version is present in the FrameworkList.xml. Considering this, the version is the one that is in the AssemblyVersion property or the FileVersion property? Because, looking at the GitHub advisory it seems they are using the FileVersion to tell if the package is vulnerable or not. Microsoft Security Advisory CVE-2023-36049: .NET Elevation of Privilege Vulnerability CVE-2023-36049 GitHub Advisory Database

Thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant