You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
.NET Framework (Windows-only) or .NET Core: 8.0.10
Environment (local platform and source/target platforms): ubuntu.24.04-x64
Steps to Reproduce:
Install the above version of sqlpackage
Run Defender for Cloud vulnerability scanner
Did this occur in prior versions? If not - which version(s) did it work in?
(DacFx/SqlPackage/SSMS/Azure Data Studio)
CVE-2024-43484 and CVE-2024-43485 are still being detected by DfC for sqlpackage 162.4.92.3, despite being fixed in .NET Core versions 8.0.1 and 8.0.5 respectively. Can advice be given whether it is a false positive or a bug planned to be addressed? Thanks.
Steps to Reproduce:
Did this occur in prior versions? If not - which version(s) did it work in?
(DacFx/SqlPackage/SSMS/Azure Data Studio)
CVE-2024-43484 and CVE-2024-43485 are still being detected by DfC for sqlpackage 162.4.92.3, despite being fixed in .NET Core versions 8.0.1 and 8.0.5 respectively. Can advice be given whether it is a false positive or a bug planned to be addressed? Thanks.
Evidence
/usr/share/sqlpackage/sqlpackage.deps.json
The text was updated successfully, but these errors were encountered: