{"id":"GHSA-gpv5-rp6w-58r8","aliases":[],"url":"https://o3.security/vulnerability/GHSA-gpv5-rp6w-58r8","summary":"Remote code execution vulnerability in dependency System.Drawing.Common","details":"### Impact\n\nThe core Akka module depended on an old System.Configuration.ConfigurationManager version 4.7.0 which transitively depends on System.Common.Drawing v4.7.0. The System.Common.Drawing v4.7.0 is affected by a remote code execution vulnerability https://github.com/advisories/GHSA-ghhp-997w-qr28.\n\nThe real-world impact of this should be low, but users should be advised to upgrade to later versions of Akka.NET.\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\nThis issue is resolved in Akka.NET v1.4.46 and Akka.NET v1.5.0-alpha3.\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\nYou might be able to explicitly reference System.Configuration.ConfigurationManager's NuGet package and upgrade to 6.0.1 or later without upgrading Akka.NET, but it's probably best to upgrade Akka.NET itself.\n\n### References\n_Are there any links users can visit to find out more?_\n\nOriginal issue: https://github.com/akkadotnet/akka.net/issues/6226\nMSFT advisory: https://github.com/advisories/GHSA-ghhp-997w-qr28\n\n### For more information\nIf you have any questions or comments about this advisory:\n\n* Open an issue in [the Akka.NET repository](https://github.com/akkadotnet/akka.net/issues/new)\n* Contact us on [the Akka.NET Discord](https://discord.gg/GSCfPwhbWP)\n","published":"2022-11-22T00:13:44Z","modified":"2024-12-04T05:32:04.565831Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"NuGet","name":"Akka","fixedVersion":"1.4.46"},{"ecosystem":"NuGet","name":"Akka","fixedVersion":"1.5.0-alpha3"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/akkadotnet/akka.net/security/advisories/GHSA-gpv5-rp6w-58r8"},{"type":"PACKAGE","url":"https://github.com/akkadotnet/akka.net"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-04T05:32:04.565831Z"}}