Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Stop using vulnerable NuGet.CommandLine package (CVE 2022-30184) #178

Closed
duncanp-sonar opened this issue Jun 16, 2022 · 0 comments
Closed
Milestone

Comments

@duncanp-sonar
Copy link
Contributor

Description

Microsoft Security Advisory CVE 2022-30184 involves a vulnerability related to NuGet functionality, including the NuGet.CommandLine NuGet package. The vulnerability relates to credentials being leaked when publishing NuGet packages i.e. it's logically related to nuget push. See this issue for more information.

The SonarQube.Roslyn.SDK is not directly affected by the vulnerability since it only pulls packages. It never pushes.
However, third-party tooling may still flag this as a vulnerability, which generates unnecessary noise and support effort.

Upgrading the package to a patched version should be straightforward i.e. no anticipated breaking changes or changes of functionality.

@duncanp-sonar duncanp-sonar added this to the 4.2 milestone Jun 16, 2022
@duncanp-sonar duncanp-sonar changed the title Stop using vulnerable NuGet.CommandLine packge Stop using vulnerable NuGet.CommandLine package (CVE 2022-30184) Oct 17, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant