HIGH7.5
GHSA-gmc6-fwg3-75m5
Mimekit has vulnerable dependency that can lead to denial of service
Quick fix
GHSA-gmc6-fwg3-75m5 — MimeKit: upgrade to the fixed version with the command below.
dotnet add package MimeKit --version 4.7.1Details
### Summary Denial of service vulnerability.
### Details See: https://github.com/advisories/GHSA-447r-wph3-92pm and https://github.com/dotnet/announcements/issues/312
### PoC Update System.Security.Cryptography.Pkcs to 8.0.1 so that the transitive dependency with the issue gets updated
### Impact Denial of service vulnerability. Affects MimeKit (>= v3.0.0 and <= v4.7.0) when used to decrypt or verify incoming S/MIME messages as well as importing 3rd-party X.509 certificates for use with encrypting outgoing S/MIME messages.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/jstedfast/MimeKit/security/advisories/GHSA-gmc6-fwg3-75m5[WEB]
- https://github.com/dotnet/announcements/issues/312[WEB]
- https://github.com/jstedfast/MimeKit/commit/aef4eda75525848b992ce5e1f9b87399000fffb6[WEB]
- https://github.com/advisories/GHSA-447r-wph3-92pm[ADVISORY]
- https://github.com/jstedfast/MimeKit[PACKAGE]