Security Advisory Id GHSA-464c-974j-9xm6
This advisory discloses a security vulnerability Patches for components to update their dependencies to avoid references that have the GHSA-464c-974j-9xm6 security advisory: AWS CDK CodeBuild S3 Log Encryption Boolean Inversion.
Patch releases
| Component | Version | Where to get it |
|---|---|---|
| NServiceBus.Persistence.Sql | 8.3.3 | NuGet |
| NServiceBus.Persistence.Sql.CommandLine | 8.3.3 | NuGet or dotnet tool update --g NServiceBus. |
| NServiceBus.Persistence.Sql.ScriptBuilder | 8.3.3 | NuGet |
| NServiceBus.Persistence.Sql.TransactionalSession | 8.3.3 | NuGet |
| NServiceBus.Persistence.Sql | 9.0.3 | NuGet |
| NServiceBus.Persistence.Sql.CommandLine | 9.0.3 | NuGet or dotnet tool update --g NServiceBus. |
| NServiceBus.Persistence.Sql.ScriptBuilder | 9.0.3 | NuGet |
| NServiceBus.Persistence.Sql.TransactionalSession | 9.0.3 | NuGet |
How to know if you are affected
You are affected if you are using previous versions of any of these components, but this doesn't necessarily mean you are vulnerable.
Symptoms
For NuGet packages your projects have the setting NuGetAuditMode set to all and see transitive dependency warnings at build time that mention Particular packages.
Other components of the platform will not have any symptoms.
When to upgrade
You should upgrade immediately if you are affected. Otherwise, you should upgrade during your next maintenance window.