core icon indicating copy to clipboard operation
core copied to clipboard

CVE-2024-38801 is reported by 8.0.7 but does not appear to be listed in the 8.0.7 release notes

Open jftl6y opened this issue 1 year ago • 3 comments

URL(s)

https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.7/8.0.7.md?WT.mc_id=dotnet-35129-website

Description

According to the CVE page at https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-38081, CVE-2024-38081 is reported to be remediated by the 8.0.7 release but does not appear in the release notes. Additionally, Defender for Containers is still reporting this issue with an Ubuntu 22.04 container with dotnet 8.0.7 installed.

jftl6y avatar Jul 25 '24 18:07 jftl6y

@rbhanda

richlander avatar Jul 25 '24 19:07 richlander

The team is working on resolving this. Thanks for reporting this.

richlander avatar Jul 25 '24 22:07 richlander

Can you check again? That CVE has been updated/re-published.

richlander avatar Jul 28 '24 00:07 richlander