We use JFrog within our organization as a repository for Nuget packages. On those packages vulnerability scans are performed for specific projects or teams for the nuget packages they use in the software they implement .
We are getting vulnerability violations for System.Security.Cryptography.Xml (version 8.0.2) and System.Text.RegularExpressions (version 4.3.0). For System.Security.Cryptography.Xml we get 7 high violations and even 1 critical violation. For System.Text.RegularExpressions we get 1 high violation. By checking the dependency chain of the visual studio project in which these are used as transitive packages we found out that these are part of the dependency chain of the PowerPlatform.Dataverse.Client package. These issues we are getting in versions 1.2.26 and 1.2.27.
For both packages I will list you the dependency chains, starting from PowerPlatform.Dataverse.Client
The full dependency chain for System.Security.Cryptography.Xm is as follows:
Microsoft.PowerPlatform.Dataverse.Client 1.2.26
├── System.ServiceModel.Primitives 8.1.2
│ └── System.Security.Cryptography.Xml 8.0.2
│ └── System.Security.Cryptography.Pkcs >= 8.0.1
│
└── System.ServiceModel.Http 8.1.2
└── System.ServiceModel.Primitives 8.1.2
└── System.Security.Cryptography.Xml 8.0.2
└── System.Security.Cryptography.Pkcs >= 8.0.1
The full dependency chain for System.Text.RegularExpressions is as follows:
Microsoft.PowerPlatform.Dataverse.Client 1.2.26
├── System.Runtime.Serialization.Xml 4.3.0
│ ├── System.Private.DataContractSerialization 4.3.0
│ │ └── System.Text.RegularExpressions 4.3.0
│ │
│ └── System.Xml.ReaderWriter 4.3.0
│ └── System.Text.RegularExpressions 4.3.0
│
├── System.Private.DataContractSerialization 4.3.0
│ ├── System.Text.RegularExpressions 4.3.0
│ ├── System.Xml.ReaderWriter 4.3.0
│ │ └── System.Text.RegularExpressions 4.3.0
│ └── System.Xml.XmlSerializer 4.3.0
│ └── System.Text.RegularExpressions 4.3.0
│
└── System.Runtime.Serialization.Xml 4.3.0
└── System.Private.DataContractSerialization 4.3.0
└── System.Text.RegularExpressions 4.3.0
Can you fix these vulnerability violations in the dependency chain for PowerPlatform.Dataverse.Client.
We use JFrog within our organization as a repository for Nuget packages. On those packages vulnerability scans are performed for specific projects or teams for the nuget packages they use in the software they implement .
We are getting vulnerability violations for System.Security.Cryptography.Xml (version 8.0.2) and System.Text.RegularExpressions (version 4.3.0). For System.Security.Cryptography.Xml we get 7 high violations and even 1 critical violation. For System.Text.RegularExpressions we get 1 high violation. By checking the dependency chain of the visual studio project in which these are used as transitive packages we found out that these are part of the dependency chain of the PowerPlatform.Dataverse.Client package. These issues we are getting in versions 1.2.26 and 1.2.27.
For both packages I will list you the dependency chains, starting from PowerPlatform.Dataverse.Client
The full dependency chain for System.Security.Cryptography.Xm is as follows:
The full dependency chain for System.Text.RegularExpressions is as follows:
Can you fix these vulnerability violations in the dependency chain for PowerPlatform.Dataverse.Client.