Skip to content

CVE-2021-41355 (Medium) detected in system.directoryservices.protocols.4.7.0.nupkg #29

@mend-for-github-com

Description

@mend-for-github-com

CVE-2021-41355 - Medium Severity Vulnerability

Vulnerable Library - system.directoryservices.protocols.4.7.0.nupkg

Provides the methods defined in the Lightweight Directory Access Protocol (LDAP) version 3 (V3) and ...

Library home page: https://api.nuget.org/packages/system.directoryservices.protocols.4.7.0.nupkg

Path to dependency file: /Activities/Database/UiPath.Database/UiPath.Database.csproj

Path to vulnerable library: /tmp/ws-ua_20230620162214_SSRFPG/dotnet_EGMXVM/20230620162214/system.directoryservices.protocols/4.7.0/system.directoryservices.protocols.4.7.0.nupkg

Dependency Hierarchy:

  • oracle.manageddataaccess.core.3.21.1.nupkg (Root Library)
    • system.directoryservices.protocols.4.7.0.nupkg (Vulnerable Library)

Found in base branch: develop

Vulnerability Details

.NET Core and Visual Studio Information Disclosure Vulnerability

Publish Date: 2021-10-13

URL: CVE-2021-41355

CVSS 3 Score Details (5.7)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Adjacent
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-9cxh-gqpx-qc5m

Release Date: 2021-10-13

Fix Resolution: system.directoryservices.protocols - 5.0.1

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions