Skip to content

Critical DDOS vulnerability in Microsoft.TeamFoundationServer.Client 20.257.0-preview System.Text.RegularExpressions 4.3.0 #37

@bjorngoa

Description

@bjorngoa

A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from GHSA-xhfc-gr8f-ffwc, GHSA-5f2m-466j-3848.

Transitive dependency System.Text.RegularExpressions 4.3.0 is introduced via
Microsoft.TeamFoundationServer.Client 20.257.0-preview System.Text.RegularExpressions 4.3.0

Is there any fix in any of the previews for this?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions