Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Vulnerabilities in Microsoft.NET.SDK.Functions 3.0.11 #521

Open
ginoey opened this issue Jun 24, 2021 · 1 comment
Open

Security Vulnerabilities in Microsoft.NET.SDK.Functions 3.0.11 #521

ginoey opened this issue Jun 24, 2021 · 1 comment

Comments

@ginoey
Copy link

ginoey commented Jun 24, 2021

Hello, I am using Microsoft.NET.SDK.Functions 3.0.11 for my Azure function App. I am getting vulnerabilities in two of the subcomponents which is referred by Microsoft.NET.SDK.Functions 3.0.11 during JFrog X-Ray scanning.

  1. System.Net.Sockets:4.3.0 - A denial of service vulnerability exists when .NET Core improperly handles web requests, aka '.NET Core Denial of Service Vulnerability'. Severity- High
  2. System.Security.Cryptography.X509Certificates:4.3.2 .NET Core and Visual Studio Denial of Service Vulnerability. Severity: Medium

I tried to downgrade the System.Net.Sockets to the lower version 4.1.0 which dont have any security vulnerability and unable to proceed due to this version is not supported by the Microsoft.NET.SDK.Functions 3.0.11.

Could you please let me know how can I resolve this or is there any plan for the future release for fixing of this issue.

Thanks
Gino Varghese

@ginoey
Copy link
Author

ginoey commented Jul 21, 2021

Hello,
Do you have any updates on the issue that I reported earlier?
Regards
Gino Varghese

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants