mbdavid / LiteDB

LiteDB - A .NET NoSQL Document Store in a single data file
http://www.litedb.org
MIT License
8.35k stars 1.22k forks source link

[BUG] CVE is fixed in v5 but v4, we are not able to migrate yet #2466

Open cfauchere opened 2 months ago

cfauchere commented 2 months ago

Version .net6 lite is 4.14

Describe the bug This CVE was fixed in 5.0.13 but we cannot migrate yet to 5.x. The CVE is a show stopper for some of our customers.

Expected behavior Fix the CVE in v4

Additional context Can we backport the CVE fix that was provided? Here is an attempt