Repository navigation
Transitive reference to vulnerable packages #2294
Description
Activity
@flacidsnake This will be fixed in 5.2 preview 5 and 5.1.vNext as I understand it - in the meantime you can add explicit references
deprecated
@flacidsnake This will be fixed in 5.2 preview 5 and 5.1.vNext as I understand it - in the meantime you can add explicit references
Thanks for your answer. Unfortunately, updating those packages explicitly in my Azure Function results in Error 500.
@flacidsnake Error 500 is an http error, and not relevant in this context, you need to check your logs for the exact error and stack trace if you want help here.
This has been addressed on #2290 and will be shipped with the next hotfix to 5.1.
- added a commit that references this issue
on Jan 15, 2024 - added a commit that references this issue
on Jan 30, 2024 @flacidsnake Error 500 is an http error, and not relevant in this context, you need to check your logs for the exact error and stack trace if you want help here.
@ErikEJ Just updated to the latest stable release, but the error remains. This is the error output:
[2024-01-30T11:46:17.697Z] Executed 'SaveData' (Failed, Id=975e76a4-c444-4f32-860d-8c1504e629a8, Duration=282ms) [2024-01-30T11:46:17.699Z] System.Private.CoreLib: Exception while executing function: SaveData. ProjectData: Could not load file or assembly 'Microsoft.IdentityModel.Tokens, Version=6.35.0.0, Culture=neutral, PublicKeyToken=31bf3876ad364e35'. The system cannot find the file specified.The library is in the bin folder, but it won't load.. Seems to be a problem with Azure Functions. The workaround to fix this is to add
<_FunctionsSkipCleanOutput>true</_FunctionsSkipCleanOutput>in thecsprojfile.The odd thing is that it works if using
Microsoft.Data.SqlClientversion5.1.1, which uses version6.24.0.0ofMicrosoft.IdentityModel.JsonWebTokensandMicrosoft.IdentityModel.JsonWebTokens🤯I'm using .net6.0 and Azure Functions v4.
@flacidsnake I think you need to address this with Azur Functions support
- added a commit that references this issue
on Jan 30, 2024

Microsoft.Data.SqlClient 5.1.4 references vulnerable versions of Microsoft.IdentityModel.JsonWebTokens and System.IdentityModel.Tokens.Jwt
Vulnerabilities associated:
https://github.com/advisories/GHSA-8g9c-28fc-mcx2
https://github.com/advisories/GHSA-59j7-ghrg-fj52