microsoft.aspnetcore.dataprotection.azurestorage.2.0.1.nupkg: 1 vulnerabilities (highest severity is: 7.5) unreachable #9
Labels
Mend: dependency security vulnerability
Security vulnerability detected by Mend
Vulnerable Library - microsoft.aspnetcore.dataprotection.azurestorage.2.0.1.nupkg
Path to dependency file: /dvcsharp-core-api.csproj
Path to vulnerable library: /home/wss-scanner/.nuget/packages/microsoft.data.odata/5.8.2/microsoft.data.odata.5.8.2.nupkg
Found in HEAD commit: 21f9b3d8a5499484535381f975f1b15ceb2519a9
Vulnerabilities
Unreachable
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2018-8269
Vulnerable Library - microsoft.data.odata.5.8.2.nupkg
Classes to serialize, deserialize and validate OData JSON payloads.
Library home page: https://api.nuget.org/packages/microsoft.data.odata.5.8.2.nupkg
Path to dependency file: /dvcsharp-core-api.csproj
Path to vulnerable library: /home/wss-scanner/.nuget/packages/microsoft.data.odata/5.8.2/microsoft.data.odata.5.8.2.nupkg
Dependency Hierarchy:
Found in HEAD commit: 21f9b3d8a5499484535381f975f1b15ceb2519a9
Found in base branch: master
Reachability Analysis
The vulnerable code is unreachable
Vulnerability Details
A denial of service vulnerability exists when OData Library improperly handles web requests, aka "OData Denial of Service Vulnerability." This affects Microsoft.Data.OData.
Publish Date: 2018-09-13
URL: CVE-2018-8269
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Release Date: 2018-09-13
Fix Resolution: Microsoft.Data.OData - 5.8.4
The text was updated successfully, but these errors were encountered: