Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2024-21386 AspNetCore.HealthChecks.UI.Client/8.0.1 - upgrade Microsoft.Extensions.Diagnostics.HealthChecks #2250

Closed
rsrinivasanhome opened this issue Jun 26, 2024 · 2 comments
Labels
dependencies Pull requests that update a dependency file
Milestone

Comments

@rsrinivasanhome
Copy link

CVE-2024-21386 - AspNetCore.HealthChecks.UI.Client/8.0.1

https://nvd.nist.gov/vuln/detail/CVE-2024-21386

Upgrade nugget: Microsoft.Extensions.Diagnostics.HealthChecks/8.0.0 to https://www.nuget.org/packages/Microsoft.Extensions.Diagnostics.HealthChecks/8.0.6

@Alirexaa Alirexaa added the dependencies Pull requests that update a dependency file label Jun 27, 2024
@Alirexaa Alirexaa added this to the V 8.1 milestone Jun 27, 2024
@adamsitnik
Copy link
Collaborator

Hi @rsrinivasanhome

Why do you believe that updating Microsoft.Extensions.Diagnostics.HealthChecks would solve the referenced CVE?

According to my understanding the bug was in the Microsoft.AspNetCore.App so the users should just update their .NET SDK?

cc @rbhanda @blowdart @Alirexaa

@blowdart
Copy link

blowdart commented Jun 28, 2024

Updating the SDK or runtime is the correct way to patch nearly all .NET CVEs now.

.NET does't update dependencies like this to reduce churn and to ensure that packages are still usable by users who haven't patched their runtimes yet, so we won't take a PR like this in the .NET repos.

Whilst no doubt well intentioned I suggest closing the PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
4 participants