dotnet / core

.NET news, announcements, release notes, and more!
https://dot.net
MIT License
21.04k stars 4.9k forks source link

CVE-2024-38801 is reported by 8.0.7 but does not appear to be listed in the 8.0.7 release notes #9429

Open jftl6y opened 4 months ago

jftl6y commented 4 months ago

URL(s)

https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.7/8.0.7.md?WT.mc_id=dotnet-35129-website

Description

According to the CVE page at https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-38081, CVE-2024-38081 is reported to be remediated by the 8.0.7 release but does not appear in the release notes. Additionally, Defender for Containers is still reporting this issue with an Ubuntu 22.04 container with dotnet 8.0.7 installed.

richlander commented 4 months ago

@rbhanda

richlander commented 4 months ago

The team is working on resolving this. Thanks for reporting this.

richlander commented 4 months ago

Can you check again? That CVE has been updated/re-published.