You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The current Microsoft.Data.SqlClient packages (release 5.1.2 & preview 5.2.0-preview3.23201.1) have Remote Code Execution Vulnerability CVE-2023-36414 through a dependency on Azure.Identity 1.7.0/1.8.0.
This also affects downstream packages such as Microsoft.EntityFrameworkCore.SqlServer.
You can fix this by updating to Azure.Identity 1.10.2 or later.
The text was updated successfully, but these errors were encountered:
Closing as duplicate of many other closed issues. such as #2195. Fix is already merged in our main branch and will be available in our next preview and GA release.
The current Microsoft.Data.SqlClient packages (release 5.1.2 & preview 5.2.0-preview3.23201.1) have Remote Code Execution Vulnerability CVE-2023-36414 through a dependency on Azure.Identity 1.7.0/1.8.0.
This also affects downstream packages such as Microsoft.EntityFrameworkCore.SqlServer.
You can fix this by updating to Azure.Identity 1.10.2 or later.
The text was updated successfully, but these errors were encountered: