aspnet / AspNetKatana

Microsoft's OWIN implementation, the Katana project
Apache License 2.0
959 stars 331 forks source link

Having vulnerabilities on Microsoft.Owin.Security.OpenIdConnect, 4.2.2 #505

Closed luanhang1807 closed 1 year ago

luanhang1807 commented 1 year ago

Hi Recently I have run dependency-check tool from https://github.com/jeremylong/DependencyCheck/releases/tag/v8.2.1 and It reported Vulnerabilities that have ID are CVE-2007-1652 (https://nvd.nist.gov/vuln/detail/CVE-2007-1652) and CVE-2007-1651 (https://nvd.nist.gov/vuln/detail/CVE-2007-1651)

I appreciate it if you can tell me how to fix these issues.

image

Tratcher commented 1 year ago

That tool appears to be wrong, those CVEs are unrelated. https://github.com/jeremylong/DependencyCheck/issues/3059

ghost commented 1 year ago

This issue has been resolved and has not had any activity for 1 day. It will be closed for housekeeping purposes.

See our Issue Management Policies for more information.