Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-24mc-gc52-47jv

Опубликовано: 30 окт. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.5
CVSS3: 5.3

Описание

ICG.AspNetCore.Utilities.CloudStorage's Secure Token Durations Different Than Expected

Impact

Users of this library that set a duration for a SAS Uri with a value other than 1 hour may have generated a URL with a duration that is longer, or shorter than desired.

Users not implemented SAS Uri's are unaffected.

Patches

This issue was resolved in version 8.0.0 of the library, all users should update to this version ASAP.

Workarounds

None

Пакеты

Наименование

ICG.AspNetCore.Utilities.CloudStorage

nuget
Затронутые версииВерсия исправления

< 8.0.0

8.0.0

EPSS

Процентиль: 29%
0.00103
Низкий

5.5 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 5.3
nvd
10 месяцев назад

ICG.AspNetCore.Utilities.CloudStorage is a collection of cloud storage utilities to assist with the management of files for cloud upload. Users of this library that set a duration for a SAS Uri with a value other than 1 hour may have generated a URL with a duration that is longer, or shorter than desired. Users not implemented SAS Uri's are unaffected. This issue was resolved in version 8.0.0 of the library.

EPSS

Процентиль: 29%
0.00103
Низкий

5.5 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-284