Closed
Description
Microsoft.Data.SqlClient has a dependency on Azure.Identity with a version that is below the remediation for CVE-2023-36414.
Azure.Identity minimum version should be >= 1.10.2 in order to ensure Microsoft.Data.SqlClient is not exposing consumers to the vulnerable version.
Due to nuget operating a lowest possible version resolution, as standard, any consumer of Microsoft.Data.SqlClient who does not also specify Azure.Identity will be vulnerable.
Metadata
Metadata
Assignees
Labels
No labels
Type
Projects
Status
Closed