-
-
Notifications
You must be signed in to change notification settings - Fork 1.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Security vulnerabilities in SixLabors.ImageSharp #1394
Comments
Can we fix then soon on 2.7.1.1? |
select your project where you consume npoi in Visual Studio, open NuGet UI, go to " |
There is no plan of urgent fix for this. The security bug is about gif codec. NPOI doesn't use this feature in ImageSharp at all. |
Created #1402 |
NPOI 2.7.2 has been released. This issue is fixed then. |
NPOI Version
2.7.1
Issue Description
Our Trivy security scanner pipeline is preventing this project from being used due to a security vulnerability in the SixLabors.ImageSharp package.
Installed library version: 2.1.8
Fixed versions: 2.1.9, 3.1.5
CVE-2024-41132 (https://avd.aquasec.com/nvd/2024/cve-2024-41132/)
CVE-2024-41131 (https://avd.aquasec.com/nvd/2024/cve-2024-41131/)
I have not created a PR for this as I did not want this to conflict with #1390
The text was updated successfully, but these errors were encountered: