Skip to content

Conversation

@ramonsmits
Copy link
Member

@ramonsmits ramonsmits commented Jan 18, 2024

Bump Microsoft.Data.SqlClient from 2.1.2 to 2.1.7

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-0056

Symptoms

Users are vulnerable due to a security issue in Microsoft.Data.SqlClient as announced in
CVE-2024-0056

Who's affected

NServiceBus SQL Transport users.

Root cause

See details in public CVE-2024-0056

@ramonsmits ramonsmits self-assigned this Jan 18, 2024
@ramonsmits ramonsmits added this to the 4.33.2 milestone Jan 18, 2024
@ramonsmits ramonsmits added Bug dependencies Pull requests that update a dependency file labels Jan 18, 2024
@ramonsmits ramonsmits enabled auto-merge (squash) January 18, 2024 14:05
@ramonsmits ramonsmits changed the base branch from release-4.33 to 4.33-updated-ravendb5-license January 19, 2024 18:05
@ramonsmits ramonsmits changed the base branch from 4.33-updated-ravendb5-license to release-4.33 January 19, 2024 18:06
@ramonsmits ramonsmits force-pushed the 4.33-Microsoft.Data.SqlClient branch from f3066ff to b650a5a Compare January 19, 2024 18:15
@ramonsmits ramonsmits disabled auto-merge January 22, 2024 08:48
@ramonsmits ramonsmits enabled auto-merge (rebase) January 22, 2024 08:52
@ramonsmits ramonsmits merged commit c52eaa1 into release-4.33 Jan 22, 2024
@ramonsmits ramonsmits deleted the 4.33-Microsoft.Data.SqlClient branch January 22, 2024 08:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Bug dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants