issues
search
riskfirst
/
riskfirst.hateoas
Powerful HATEOAS functionality for .NET web api
MIT License
78
stars
25
forks
source link
Information disclosure vulnerability exists in System.Security.Cryptography.Xml 4.5.0
#52
Open
ejarvi
opened
6 months ago
ejarvi
commented
6 months ago
Actual
Nuget package RiskFirst.Hateoas 3.1.1 uses System.Security.Cryptography.Xml 4.5.0
Information disclosure vulnerability exists in System.Security.Cryptography.Xml 4.5.0
Expected
Upgrade Security.Cryptography.Xml from 4.5.0 to 4.7.1 to fix the vulnerability.
References
https://github.com/dotnet/aspnetcore/security/advisories/GHSA-vh55-786g-wjwj
https://www.nuget.org/packages/RiskFirst.Hateoas
Actual
Expected
References