Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Microsoft.IdentityModel.JsonWebTokens version 7.5.2 has dependencies with CRITICAL CVE findings #457

Open
stefnees opened this issue Nov 13, 2024 · 4 comments
Assignees
Labels

Comments

@stefnees
Copy link

stefnees commented Nov 13, 2024

  • DocuSign.eSign.dll/8.0.1 has dependency:
    • Microsoft.IdentityModel.JsonWebTokens/7.5.2 has dependency:
      • System.Text.Encodings.Web/4.7.2
      • System.Text.Json/4.72 has dependency:
        - System.Text.Encodings.Web/4.7.1

Upgrading to at least 7.7.0 gets past the System.Text.Json version that pulls in the dependency with the issue.
Reference: CVE-2021-26701
dotnet/announcements#178

@garg-mudit
Copy link
Contributor

Hi @stefnees ,
We will look into the issue and try to update the version as soon as possible.

Thank You.

@stefnees
Copy link
Author

Thank you so much for the quick response. It would be great to get this resolved so that our security scans will quit yelling at us. I look forward to a resolution. :)

@garg-mudit
Copy link
Contributor

Hi @stefnees ,
The issue should be resolved with following release:
https://github.com/docusign/docusign-esign-csharp-client/releases/tag/v8.0.2.

Please let us know if there is something that still requires change to fix the issue.

Thank You.

@garg-mudit garg-mudit self-assigned this Nov 18, 2024
@stefnees
Copy link
Author

stefnees commented Nov 18, 2024 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants