Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

System.Security.Cryptography.Pkcs dependency has severe vulnerability #288

Open
tdhooten opened this issue Dec 11, 2023 · 2 comments
Open

Comments

@tdhooten
Copy link

tdhooten commented Dec 11, 2023

The dependency on System.Security.Cryptography.Pkcs version 6.0.1 has the following CVE-2023-29331:

GHSA-555c-2p6r-68mm

Please bump the version to at least 7.0.2 as soon as possible.

@mganss
Copy link
Owner

mganss commented Dec 12, 2023

This is an indirect dependency introduced through NPOI. I have reported to the NPOI team.

@mganss
Copy link
Owner

mganss commented Dec 13, 2023

This has been resolved in nissl-lab/npoi#1183. Will update as soon as NPOI releases a new version.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants