Skip to content

Microsoft Security Advisory CVE-2024-43485#442

Merged
axunonb merged 1 commit intoaxuno:mainfrom
axunonb:pr/System.Text.Json_Vulnerability
Oct 11, 2024
Merged

Microsoft Security Advisory CVE-2024-43485#442
axunonb merged 1 commit intoaxuno:mainfrom
axunonb:pr/System.Text.Json_Vulnerability

Conversation

@axunonb
Copy link
Member

@axunonb axunonb commented Oct 11, 2024

Microsoft is releasing this security advisory to provide information about a vulnerability in System.Text.Json 6.0.x and 8.0.x. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

In System.Text.Json 6.0.x and 8.0.x, applications which deserialize input to a model with an [ExtensionData] property can be vulnerable to an algorithmic complexity attack resulting in Denial of Service.

Microsoft is releasing this security advisory to provide information about a vulnerability in System.Text.Json 6.0.x and 8.0.x. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

In System.Text.Json 6.0.x and 8.0.x, applications which deserialize input to a model with an [ExtensionData] property can be vulnerable to an algorithmic complexity attack resulting in Denial of Service.
@codecov
Copy link

codecov bot commented Oct 11, 2024

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 97%. Comparing base (c097ea6) to head (aaa12df).
Report is 1 commits behind head on main.

Additional details and impacted files
@@         Coverage Diff         @@
##           main   #442   +/-   ##
===================================
  Coverage    97%    97%           
===================================
  Files        96     96           
  Lines      3434   3434           
===================================
  Hits       3317   3317           
  Misses      117    117           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@axunonb axunonb merged commit c33b9a5 into axuno:main Oct 11, 2024
@axunonb axunonb deleted the pr/System.Text.Json_Vulnerability branch October 11, 2024 16:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant