dmyers87 / Commercial-Marketplace-SaaS-Manual-On-Boarding

Contoso Sample
MIT License
0 stars 0 forks source link

CVE-2024-30105 (High) detected in system.text.json.5.0.1.nupkg - autoclosed #20

Closed mend-for-github-com[bot] closed 2 months ago

mend-for-github-com[bot] commented 2 months ago

CVE-2024-30105 - High Severity Vulnerability

Vulnerable Library - system.text.json.5.0.1.nupkg

Provides high-performance and low-allocating types that serialize objects to JavaScript Object Notat...

Library home page: https://api.nuget.org/packages/system.text.json.5.0.1.nupkg

Path to dependency file: /src/CommandCenter/CommandCenter.csproj

Path to vulnerable library: /home/wss-scanner/.nuget/packages/system.text.json/5.0.1/system.text.json.5.0.1.nupkg

Dependency Hierarchy: - ercenk.microsoft.marketplace.1.0.0-preview5.nupkg (Root Library) - :x: **system.text.json.5.0.1.nupkg** (Vulnerable Library)

Found in HEAD commit: b363cbedbe66b77c2fdc0201b10a4714fabf1499

Found in base branch: main

Vulnerability Details

.NET Core and Visual Studio Denial of Service Vulnerability

Publish Date: 2024-07-09

URL: CVE-2024-30105

CVSS 3 Score Details (7.5)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: None - Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://github.com/advisories/GHSA-hh2w-p6rv-4g7w

Release Date: 2024-07-09

Fix Resolution: System.Text.Json - 8.0.4

mend-for-github-com[bot] commented 2 months ago

:heavy_check_mark: This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.