Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

System.Data.SqlClient needs a version bumb from 4.5.1 to 4.8.3 #67

Closed
mattiaskagstrom opened this issue Dec 8, 2021 · 4 comments
Closed

Comments

@mattiaskagstrom
Copy link

@dotMorten
Copy link
Owner

Why ? Please include a bit more info or references

@mattiaskagstrom
Copy link
Author

Sonatype OSS Index returns this for versions below 4.8.1

[CVE-2014-0257] Improper Input Validation
[CVE-2014-0253] Improper Input Validation
[CVE-2014-4072] Resource Management Errors
[CVE-2014-4149] Improper Input Validation
[CVE-2014-1806] Improper Control of Generation of Code ("Code Injection")
[CVE-2015-1673] Permissions, Privileges, and Access Controls
[CVE-2015-1648] Data Handling
[CVE-2014-4121] Resource Management Errors
[CVE-2015-1672] Cryptographic Issues
[CVE-2015-2504] Improper Restriction of Operations within the Bounds of a Memory Buffer
[CVE-2014-4073] Permissions, Privileges, and Access Controls
[CVE-2015-6096] Information Exposure
[CVE-2015-1671] Data Handling
[CVE-2015-1670] Information Exposure
[CVE-2015-2460] Improper Input Validation
[CVE-2015-6099] Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting")
[CVE-2015-2526] Code

@dotMorten
Copy link
Owner

Thanks. So 4.8.1 and not 4.8.3 is needed?

@mattiaskagstrom
Copy link
Author

Yeah, 4.8.1 and above are all fine according to OSS

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants