8000 System.Text.Json in v8.0.2 of dotnet has a known vulnerability and its recommended to update to v8.0.4 · Issue #376 · serilog/serilog-aspnetcore · GitHub
[go: up one dir, main page]

Skip to content
System.Text.Json in v8.0.2 of dotnet has a known vulnerability and its recommended to update to v8.0.4 #376
Closed
@fhsteve

Description

@fhsteve

The Serilog maintainers want you to have a great experience using Serilog, and will happily track down and resolve bugs. We all have limited time, though, so please think through all of the factors that might be involved and include as much useful information as possible 😊.

ℹ If the problem is caused by a sink or other related package, please try to track down the correct repository for that package and create the report there: this tracker is for the Serilog.AspNetCore package only.

Description
There is a known vulnerability in System.Text.Json for v8.0.2 of dotnet which was flagged to me by our package scanners during CI/CD.
Its recommended to update to v8.0.4
See microsoft advisory here -> GHSA-hh2w-p6rv-4g7w

Reproduction
n/a

Expected behavior
n/a

Relevant package, tooling and runtime versions
Serilog v8.0.1+

Additional context
n/a

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

      0