Skip to content

Is System.drawing.common vulnerable to CVE-2021-24112 in .Net SDK 6.0 #29927

Open
@git-smita

Description

@git-smita

As per the github advisory System.Drawing.Common ([NuGet]) is patched in v4.7.2 - GHSA-rxg9-xrhp-64gj

But .dotnet SDK 6.0.405 contains v4.7.0. is it possible to publish/get a confirmation that SDK versions other than what's list in the
advisory https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-24112 are not vulnerable.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions