DacFx, SqlPackage, and other SQL development libraries enable declarative database development and database portability across SQL versions and environments. Share feedback here on dacpacs, bacpacs, and SQL projects.
.NET Framework (Windows-only) or .NET Core: 8.0.10
Environment (local platform and source/target platforms): ubuntu.24.04-x64
Steps to Reproduce:
Install the above version of sqlpackage
Run Defender for Cloud vulnerability scanner
Did this occur in prior versions? If not - which version(s) did it work in?
(DacFx/SqlPackage/SSMS/Azure Data Studio)
CVE-2024-43484 and CVE-2024-43485 are still being detected by DfC for sqlpackage 162.4.92.3, despite being fixed in .NET Core versions 8.0.1 and 8.0.5 respectively. Can advice be given whether it is a false positive or a bug planned to be addressed? Thanks.
Steps to Reproduce:
Did this occur in prior versions? If not - which version(s) did it work in?
(DacFx/SqlPackage/SSMS/Azure Data Studio)
CVE-2024-43484 and CVE-2024-43485 are still being detected by DfC for sqlpackage 162.4.92.3, despite being fixed in .NET Core versions 8.0.1 and 8.0.5 respectively. Can advice be given whether it is a false positive or a bug planned to be addressed? Thanks.
Evidence /usr/share/sqlpackage/sqlpackage.deps.json