Skip to content

Update to SharpCompress 0.30.0 due to CVE-2021-39208 #230

@Mario-Hofstaetter

Description

@Mario-Hofstaetter

We have been alerted by our Dependency-Track server that

<PackageReference Include="SharpCompress" Version="0.23.0" />

currently used by Ductus.FluentDocker is affected by CVE-2021-39208.

See also https://nvd.nist.gov/vuln/detail/CVE-2021-39208
This has been fixed in SharpCompress >= 0.29.0.

While this is low in Impact (CVSS Base Score 4.3) @mariotoffia please consider upgrading the dependency, because users of your library need to security audit this.

There was an automatic PR #213 for this, but the SharpCompress release notes did not even mention the CVE.

Thanks ❤️

Metadata

Metadata

Assignees

Labels

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions