Bug 2312610
Summary: | dotnet7.0: Cross-site Scripting (XSS) in serialize-javascript [fedora-39] | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Abhishek Raj <abhraj> |
Component: | dotnet7.0 | Assignee: | Omair Majid <omajid> |
Status: | CLOSED WONTFIX | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 39 | CC: | omajid |
Target Milestone: | --- | Keywords: | Security, SecurityTracking |
Target Release: | --- | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | {"flaws": ["bf271af9-6b18-411e-9c39-8956f35db96f"]} | ||
Fixed In Version: | Doc Type: | No Doc Update | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2024-09-16 22:30:31 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 2312579 |
Description
Abhishek Raj
2024-09-16 18:01:46 UTC
.NET 7 (dotnet7.0) reached its End of Life on May 14, 2024: https://devblogs.microsoft.com/dotnet/dotnet-7-end-of-support/ It's likely affected by a number of security issues, not just this one. I have no plans to update .NET 7 or fix any issues in it. My advice to everyone is to uninstall .NET 7 and use a supported version of .NET (eg, .NET 6 or .NET 8) instead. |