VDB
Sign up
HIGH7.5

GHSA-jrjw-qgr2-wfcg

YARP Denial of Service Vulnerability

Quick fix

GHSA-jrjw-qgr2-wfcg — Yarp.ReverseProxy: upgrade to the fixed version with the command below.

dotnet add package Yarp.ReverseProxy --version 1.1.2

Details

### Impact A denial of service vulnerability exists in YARP.

### Patches If you're using YARP 1.x, you should update to NuGet package version [1.1.2](https://www.nuget.org/packages/Yarp.ReverseProxy/1.1.2). If you're using YARP 2.0.0, you should update to NuGet package version [2.0.1](https://www.nuget.org/packages/Yarp.ReverseProxy/2.0.1).

You can do so by updating the `PackageReference` in your `.csproj` file ```diff <ItemGroup> - <PackageReference Include="Yarp.ReverseProxy" Version="2.0.0" /> - <PackageReference Include="Yarp.Telemetry.Consumption" Version="2.0.0" /> + <PackageReference Include="Yarp.ReverseProxy" Version="2.0.1" /> + <PackageReference Include="Yarp.Telemetry.Consumption" Version="2.0.1" /> </ItemGroup> ``` or by selecting `2.0.1` in the NuGet UI inside Visual Studio (`Manage NuGet Packages` / `Updates`)

### References

[CVE-2023-33141](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33141)

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/Yarp.ReverseProxy
Introduced in: 0Fixed in: 1.1.2
Fixdotnet add package Yarp.ReverseProxy --version 1.1.2
NuGet/Yarp.ReverseProxy
Introduced in: 2.0.0Fixed in: 2.0.1
Fixdotnet add package Yarp.ReverseProxy --version 2.0.1

References