-
-
Notifications
You must be signed in to change notification settings - Fork 104
Update to SharpCompress 0.30.0 due to CVE-2021-39208 #230
Copy link
Copy link
Closed
Description
We have been alerted by our Dependency-Track server that
<PackageReference Include="SharpCompress" Version="0.23.0" />currently used by Ductus.FluentDocker is affected by CVE-2021-39208.
See also https://nvd.nist.gov/vuln/detail/CVE-2021-39208
This has been fixed in SharpCompress >= 0.29.0.
While this is low in Impact (CVSS Base Score 4.3) @mariotoffia please consider upgrading the dependency, because users of your library need to security audit this.
There was an automatic PR #213 for this, but the SharpCompress release notes did not even mention the CVE.
Thanks ❤️
Reactions are currently unavailable