Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2024-38801 is reported by 8.0.7 but does not appear to be listed in the 8.0.7 release notes #9429

Open
jftl6y opened this issue Jul 25, 2024 · 3 comments

Comments

@jftl6y
Copy link

jftl6y commented Jul 25, 2024

URL(s)

https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.7/8.0.7.md?WT.mc_id=dotnet-35129-website

Description

According to the CVE page at https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-38081, CVE-2024-38081 is reported to be remediated by the 8.0.7 release but does not appear in the release notes. Additionally, Defender for Containers is still reporting this issue with an Ubuntu 22.04 container with dotnet 8.0.7 installed.

@richlander
Copy link
Member

@rbhanda

@richlander
Copy link
Member

The team is working on resolving this. Thanks for reporting this.

@richlander
Copy link
Member

Can you check again? That CVE has been updated/re-published.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants