Replies: 1 comment
-
|
Security issues and bugs should be reported privately to the Microsoft Security Response Center (MSRC), either by emailing [email protected] or via the portal at https://msrc.microsoft.com/. You should receive a response within 24 hours. If for some reason you do not, please follow up via email to ensure we received your original message. Further information, including the MSRC PGP key, can be found in the MSRC Report an Issue FAQ. Please do not open issues for anything you think might have a security implication. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hi folks,
We have an application using the latest version of the Snapshot Collector package, and .NET 8.0, which we are running Veracode application security scans on. Those scans are reporting a "Very High" error within this package, citing this CWE: https://cwe.mitre.org/data/definitions/78.html , CWE 78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'). Veracode says that the location of this error is: microsoft_applicationinsights_snapshotcollector_dll.Microsoft.ApplicationInsights.SnapshotCollector.UploaderProcess .
Can this be addressed/fixed? Please let me know.
Thanks!
Beta Was this translation helpful? Give feedback.
All reactions