-
-
Notifications
You must be signed in to change notification settings - Fork 1.4k
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
Security vulnerabilities in SixLabors.ImageSharp #1394
Comments
Can we fix then soon on 2.7.1.1? |
select your project where you consume npoi in Visual Studio, open NuGet UI, go to " |
There is no plan of urgent fix for this. The security bug is about gif codec. NPOI doesn't use this feature in ImageSharp at all. |
Created #1402 |
NPOI 2.7.2 has been released. This issue is fixed then. |
NPOI Version
2.7.1
Issue Description
Our Trivy security scanner pipeline is preventing this project from being used due to a security vulnerability in the SixLabors.ImageSharp package.
Installed library version: 2.1.8
Fixed versions: 2.1.9, 3.1.5
CVE-2024-41132 (https://avd.aquasec.com/nvd/2024/cve-2024-41132/)
CVE-2024-41131 (https://avd.aquasec.com/nvd/2024/cve-2024-41131/)
I have not created a PR for this as I did not want this to conflict with #1390
The text was updated successfully, but these errors were encountered: