Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[release/5.0-preview7] Disallow unrestricted polymorphic deserialization in DataSet #39314

Conversation

GrabYourPitchforks
Copy link
Member

Fixes CVE-2020-1147
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-1147
See also https://go.microsoft.com/fwlink/?linkid=2132227.

5.0-preview7 port from the release/3.1 branch. Only change was to the .csproj to account for some build system updates.

@ghost
Copy link

ghost commented Jul 14, 2020

Tagging subscribers to this area: @roji, @ajcvickers
Notify danmosemsft if you want to be subscribed.

@GrabYourPitchforks
Copy link
Member Author

CI's on the floor. Restarting.

/azp run runtime

@GrabYourPitchforks
Copy link
Member Author

CI's not scheduling certain test runs. However, the test legs that did run were successful, so marching forward with this.

@GrabYourPitchforks GrabYourPitchforks merged commit 53976d3 into dotnet:release/5.0-preview7 Jul 15, 2020
@GrabYourPitchforks GrabYourPitchforks deleted the dataset_cve_p7 branch July 15, 2020 06:12
@ghost ghost locked as resolved and limited conversation to collaborators Dec 8, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants