Skip to content

Commit f4f83bc

Browse files
authored
Added an explicit dependency to Microsoft.Extensions.Caching.Memory to force it to use a non-vulnerable version (#17287)
1 parent 30b114d commit f4f83bc

File tree

3 files changed

+11
-1
lines changed

3 files changed

+11
-1
lines changed

Directory.Packages.props

+4-1
Original file line numberDiff line numberDiff line change
@@ -91,5 +91,8 @@
9191
<PackageVersion Include="System.Text.RegularExpressions" Version="4.3.1" />
9292
<!-- Both OpenIddict.AspNetCore, Npoco.SqlServer and Microsoft.EntityFrameworkCore.SqlServer bring in a vulnerable version of Microsoft.IdentityModel.JsonWebTokens -->
9393
<PackageVersion Include="Microsoft.IdentityModel.JsonWebTokens" Version="7.7.1" />
94+
95+
<!-- Both OpenIddict.AspNetCore, Microsoft.EntityFrameworkCore.* bring in a vulnerable version of Microsoft.Extensions.Caching.Memory -->
96+
<PackageVersion Include="Microsoft.Extensions.Caching.Memory" Version="8.0.1" />
9497
</ItemGroup>
95-
</Project>
98+
</Project>

src/Umbraco.Cms.Api.Common/Umbraco.Cms.Api.Common.csproj

+3
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,9 @@
1515

1616
<!-- Both OpenIddict.AspNetCore, Npoco.SqlServer and Microsoft.EntityFrameworkCore.SqlServer bring in a vulnerable version of Microsoft.IdentityModel.JsonWebTokens -->
1717
<PackageReference Include="Microsoft.IdentityModel.JsonWebTokens"/>
18+
19+
<!-- Take top-level depedendency on OpenIddict.AspNetCore depends on a vulnerable version -->
20+
<PackageReference Include="Microsoft.Extensions.Caching.Memory" />
1821
</ItemGroup>
1922

2023
<ItemGroup>

src/Umbraco.Cms.Persistence.EFCore/Umbraco.Cms.Persistence.EFCore.csproj

+4
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,10 @@
77
<ItemGroup>
88
<!-- Take top-level depedendency on Azure.Identity, because Microsoft.EntityFrameworkCore.SqlServer depends on a vulnerable version -->
99
<PackageReference Include="Azure.Identity" />
10+
11+
<!-- Take top-level depedendency on Microsoft.Extensions.Caching.Memory, because Microsoft.EntityFrameworkCore.* depends on a vulnerable version -->
12+
<PackageReference Include="Microsoft.Extensions.Caching.Memory" />
13+
1014
<PackageReference Include="Microsoft.EntityFrameworkCore.SqlServer" />
1115
<PackageReference Include="Microsoft.EntityFrameworkCore.Sqlite" />
1216
<PackageReference Include="OpenIddict.EntityFrameworkCore" />

0 commit comments

Comments
 (0)