Skip to content

Dependency chain of PowerPlatform.Dataverse.client contains packages with high and critical vulnerabilities #540

Description

@JoehannusApg

We use JFrog within our organization as a repository for Nuget packages. On those packages vulnerability scans are performed for specific projects or teams for the nuget packages they use in the software they implement .

We are getting vulnerability violations for System.Security.Cryptography.Xml (version 8.0.2) and System.Text.RegularExpressions (version 4.3.0). For System.Security.Cryptography.Xml we get 7 high violations and even 1 critical violation. For System.Text.RegularExpressions we get 1 high violation. By checking the dependency chain of the visual studio project in which these are used as transitive packages we found out that these are part of the dependency chain of the PowerPlatform.Dataverse.Client package. These issues we are getting in versions 1.2.26 and 1.2.27.

For both packages I will list you the dependency chains, starting from PowerPlatform.Dataverse.Client

The full dependency chain for System.Security.Cryptography.Xm is as follows:

Microsoft.PowerPlatform.Dataverse.Client 1.2.26
├── System.ServiceModel.Primitives 8.1.2
│   └── System.Security.Cryptography.Xml 8.0.2
│       └── System.Security.Cryptography.Pkcs >= 8.0.1
│
└── System.ServiceModel.Http 8.1.2
    └── System.ServiceModel.Primitives 8.1.2
        └── System.Security.Cryptography.Xml 8.0.2
            └── System.Security.Cryptography.Pkcs >= 8.0.1

The full dependency chain for System.Text.RegularExpressions is as follows:

Microsoft.PowerPlatform.Dataverse.Client 1.2.26
├── System.Runtime.Serialization.Xml 4.3.0
│   ├── System.Private.DataContractSerialization 4.3.0
│   │   └── System.Text.RegularExpressions 4.3.0
│   │
│   └── System.Xml.ReaderWriter 4.3.0
│       └── System.Text.RegularExpressions 4.3.0
│
├── System.Private.DataContractSerialization 4.3.0
│   ├── System.Text.RegularExpressions 4.3.0
│   ├── System.Xml.ReaderWriter 4.3.0
│   │   └── System.Text.RegularExpressions 4.3.0
│   └── System.Xml.XmlSerializer 4.3.0
│       └── System.Text.RegularExpressions 4.3.0
│
└── System.Runtime.Serialization.Xml 4.3.0
    └── System.Private.DataContractSerialization 4.3.0
        └── System.Text.RegularExpressions 4.3.0

Can you fix these vulnerability violations in the dependency chain for PowerPlatform.Dataverse.Client.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions