3 ms·
That feeling when you open a brand new project in VS and immediately get: "The solution contains packages with vulnerabilities"
by r0x0r007 11mo ago
That feeling when you open a brand new project in VS and immediately get:
"The solution contains packages with vulnerabilities"
- CharlieDigital 11mo agoThat's a Good Thing rather than shipping vulnerable code.
- cm2187 11mo agoAnd now that everything is a package, it won’t get fixed with windows update. Which means that if the website isn’t actively developed and regularly deployed, it will remain vulnerable
- lsbehe 11mo agoM$ offers system wide installations. Those don't seem to be updated automatically either but at least I don't have to deploy 6 servers now.
- Uvix 11mo agoOn Linux, system-wide installations are handled through the system's package manager. On Windows, if you have the "Install updates for other Microsoft products" option enabled, .NET [Core] runtimes will be updated through Windows Update. If the domain's group policy won't let you turn it on from the UI (or if you want to turn it on programmatically for other reasons), the PowerShell 7 installer has a PowerShell script that can be adapted to do the trick: https://github.com/PowerShell/PowerShell/blob/ba02868d0fa1d724fcde39e612534d3db693eb39/assets/MicrosoftUpdate/RegisterMicrosoftUpdate.ps1 https://github.com/PowerShell/PowerShell/blob/ba02868d0fa1d7...
- lsbehe 11mo agoarchlinux doesn't offer the new version yet. https://archlinux.org/packages/extra/x86_64/aspnet-runtime/ https://archlinux.org/packages/extra/x86_64/aspnet-runtime/ Only exposing stuff behind caddy so it doesn't seem to be an issue.
- voxic11 11mo agoActually this bug is in Microsoft.AspNetCore.App.Runtime which is an implict package that comes from the runtime. So simply updating your version of the dotnet should fix any vulnerable applications.
- Traubenfuchs 11mo agoIt's pretty much the same in Javaland with maven and spring. Create a new project with the latest spring version, and maven will warn you. At this point I consider this worthless noise.
- weinzierl 11mo agoI think Spring doesn't consider vulnerabilities in one of their components to be a Spring vulnerability. At least they do not release an updated version until the next scheduled patch version, not even in the paid version. You can either wait and accept being vulnerable or update the component yourself and therefore run an unsupported and untested configuration. Doomed if you do, doomed if you don't.