Reproducing WiX Toolset Security Vulnerability to Verify Upgrade #8095
Unanswered
Sandhiya-Sivakumar
asked this question in
Questions
Replies: 1 comment
-
It's not just you; the link to the |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Dear @robmen,
We have recently become aware of a security vulnerability in the WiX Toolset v3.14.0 that we are currently using. Specifically, the vulnerability involves the handling of temporary files by the Burn component, as described here.
So we are in the process of upgrading to WiX v3.14.1, In order to ensure that the upgrade procedure we follow addresses the vulnerability, we are seeking assistance in reproducing the issue ourselves. Unfortunately, the PoC link provided in the security update is inaccessible to us.
Could you please provide guidance on how we might reproduce or access the PoC? Our intention is to gain a deeper understanding of the vulnerability and check whether the upgrade procedure resolves the vulnerability before implementing in production.
Any assistance or insights into this matter would be greatly appreciated.
Thanks.
Beta Was this translation helpful? Give feedback.
All reactions