Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-0056
HistoryJan 09, 2024 - 12:00 a.m.

CVE-2024-0056

2024-01-0900:00:00
ubuntu.com
ubuntu.com
31
cve-2024-0056
microsoft.data.sqlclient
system.data.sqlclient
nuget packages
update
unix

CVSS3

8.7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

AI Score

9.2

Confidence

High

EPSS

0.002

Percentile

52.6%

Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider
Security Feature Bypass Vulnerability

Notes

Author Note
iconstantin This issue exists in the System.Data.SqlClient and Microsoft.Data.SqlClient NuGet packages, which would need to be updated to address the vulnerability.

CVSS3

8.7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

AI Score

9.2

Confidence

High

EPSS

0.002

Percentile

52.6%