Snyk vulnerability in v3.1.2
See original GitHub issueHello,
We are using IdentityModel.OidcClient in our SDK, however Snyk is reporting a High
vulnerability (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-26701) in System.Text.Encodings.Web
that gets introduced through IdentityModel
.
Given the fact that v4 of OidcClient is still in preview, we are still using v3.
I was looking into opening a quick PR to bump this dependency in https://github.com/IdentityModel/IdentityModel, however, I can see it only has a main branch that contains v5, so I am not sure how to get this resolved.
Here is a github issue on the dotnet runtime repository with more context: https://github.com/dotnet/runtime/issues/49377
Thanks
Issue Analytics
- State:
- Created 2 years ago
- Reactions:1
- Comments:15 (10 by maintainers)
Top Results From Across the Web
mailchimp-api-v3 1.2.0 vulnerabilities
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities (in both your packages & their dependencies) and provides ...
Read more >snyk/snyk@1.7.2
Use Snyk to find, fix and monitor known vulnerabilities in your app dependencies, container images, cloud infrastructure and code. To use this ...
Read more >How to Use the Snyk CLI to Fix Vulnerabilities in ... - YouTube
Brian Vermeer, Developer Advocate at Snyk, demonstrates how you can use the Snyk CLI to fix vulnerabilities in your application.
Read more >Newest 'snyk' Questions - Stack Overflow
Snyk is a service that analyzes your code to help find and fix security vulnerabilities in your applications, containers, infrastructure-as-code ...
Read more >Snyk (@snyksec) / X
*IMPORTANT DISCLOSURE* A malicious remote code execution backdoor has been discovered in the popular bootstrap-sass Ruby gem. The gem has been downloaded ...
Read more >
Top Related Medium Post
No results found
Top Related StackOverflow Question
No results found
Troubleshoot Live Code
Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free
Top Related Reddit Thread
No results found
Top Related Hackernoon Post
No results found
Top Related Tweet
No results found
Top Related Dev.to Post
No results found
Top Related Hashnode Post
No results found
That looks good to me. I will do a final review and then release v4
This issue has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue.