GHSA-jrjw-qgr2-wfcg
YARP Denial of Service Vulnerability
Quick fix
GHSA-jrjw-qgr2-wfcg — Yarp.ReverseProxy: upgrade to the fixed version with the command below.
dotnet add package Yarp.ReverseProxy --version 1.1.2Details
### Impact A denial of service vulnerability exists in YARP.
### Patches If you're using YARP 1.x, you should update to NuGet package version [1.1.2](https://www.nuget.org/packages/Yarp.ReverseProxy/1.1.2). If you're using YARP 2.0.0, you should update to NuGet package version [2.0.1](https://www.nuget.org/packages/Yarp.ReverseProxy/2.0.1).
You can do so by updating the `PackageReference` in your `.csproj` file ```diff <ItemGroup> - <PackageReference Include="Yarp.ReverseProxy" Version="2.0.0" /> - <PackageReference Include="Yarp.Telemetry.Consumption" Version="2.0.0" /> + <PackageReference Include="Yarp.ReverseProxy" Version="2.0.1" /> + <PackageReference Include="Yarp.Telemetry.Consumption" Version="2.0.1" /> </ItemGroup> ``` or by selecting `2.0.1` in the NuGet UI inside Visual Studio (`Manage NuGet Packages` / `Updates`)
### References
[CVE-2023-33141](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33141)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.1.2dotnet add package Yarp.ReverseProxy --version 1.1.22.0.0Fixed in: 2.0.1dotnet add package Yarp.ReverseProxy --version 2.0.1References
- https://github.com/microsoft/reverse-proxy/security/advisories/GHSA-jrjw-qgr2-wfcg[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-33141[ADVISORY]
- https://github.com/microsoft/reverse-proxy[PACKAGE]
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33141[WEB]
- https://www.nuget.org/packages/Yarp.ReverseProxy/1.1.2[WEB]
- https://www.nuget.org/packages/Yarp.ReverseProxy/2.0.1[WEB]