Описание
YARP Denial of Service Vulnerability
Impact
A denial of service vulnerability exists in YARP.
Patches
If you're using YARP 1.x, you should update to NuGet package version 1.1.2. If you're using YARP 2.0.0, you should update to NuGet package version 2.0.1.
You can do so by updating the PackageReference in your .csproj file
or by selecting 2.0.1 in the NuGet UI inside Visual Studio (Manage NuGet Packages / Updates)
References
Ссылки
- https://github.com/microsoft/reverse-proxy/security/advisories/GHSA-jrjw-qgr2-wfcg
- https://nvd.nist.gov/vuln/detail/CVE-2023-33141
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33141
- https://www.nuget.org/packages/Yarp.ReverseProxy/1.1.2
- https://www.nuget.org/packages/Yarp.ReverseProxy/2.0.1
Пакеты
Yarp.ReverseProxy
<= 1.1.1
1.1.2
Yarp.ReverseProxy
= 2.0.0
2.0.1
Связанные уязвимости
Yet Another Reverse Proxy (YARP) Denial of Service Vulnerability
Yet Another Reverse Proxy (YARP) Denial of Service Vulnerability
Уязвимость обратного прокси-сервера Yet Another Reverse Proxy (YARP) Microsoft, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю вызвать отказ в обслуживании