snowflakedb / snowflake-connector-net

Snowflake Connector for .NET
Apache License 2.0
173 stars 130 forks source link

Snyk: snowflake-connector-net Microsoft.IdentityModel.JsonWebTokens 6.10.2 | Snyk ID - SNYK-DOTNET-MICROSOFTIDENTITYMODELJSONWEBTOKENS-6148656 #847

Closed github-actions[bot] closed 4 months ago

github-actions[bot] commented 5 months ago

Title: Snyk: snowflake-connector-net Microsoft.IdentityModel.JsonWebTokens 6.10.2 Additional information on Snyk can be found here: https://snyk.io/org/snowflakedb-sca-scanning-public-repo/project/6e936eea-71aa-4aa5-a46f-3ee09a811bff Repo: snowflake-connector-net CVE: CVE-2024-21319 Package Type: dotnet Package Name: Microsoft.IdentityModel.JsonWebTokens Package Version: 6.10.2 Snyk ID: SNYK-DOTNET-MICROSOFTIDENTITYMODELJSONWEBTOKENS-6148656 Vulnerability URL: http://security.snyk.io/vuln/SNYK-DOTNET-MICROSOFTIDENTITYMODELJSONWEBTOKENS-6148656 Severity: medium Introduced Date: 2024-01-11 Projects with Vulnerability: snowflakedb/snowflake-connector-net:Snowflake.Data/Snowflake.Data.csproj Target File: Snowflake.Data/Snowflake.Data.csproj JIRA Ticket: https://snowflakecomputing.atlassian.net/browse/SNOW-1005621

sfc-gh-dszmolka commented 5 months ago

https://github.com/snowflakedb/snowflake-connector-net/pull/845

sfc-gh-dszmolka commented 4 months ago

fix released with version 3.0.0, closing Issue