QID 980000

QID 980000: Dotnet (nuget) Security Update for System.DirectoryServices.Protocols (GHSA-9cxh-gqpx-qc5m)

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A Information Disclosure vulnerability exists in .NET where System.DirectoryServices.Protocols.LdapConnection may send credentials in plain text on Linux.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.7 severity.
  • CVSS V2 rated as Low - 2.9 severity.
  • Solution
    Any .NET application that uses `System.DirectoryServices.Protocols` with a vulnerable version listed below on system based on Linux.

    Package name | Vulnerable versions | Secure versions
    ------------ | ---------------- | -------------------------
    System.DirectoryServices.Protocols | 5.0.0 | 5.0.1
    Vendor References

    CVEs related to QID 980000

    Software Advisories
    Advisory ID Software Component Link
    GHSA-9cxh-gqpx-qc5m System.DirectoryServices.Protocols URL Logo github.com/advisories/GHSA-9cxh-gqpx-qc5m