Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Question about security #660

Closed
ItSkary opened this issue Jan 11, 2023 · 4 comments
Closed

Question about security #660

ItSkary opened this issue Jan 11, 2023 · 4 comments
Assignees
Labels

Comments

@ItSkary
Copy link

ItSkary commented Jan 11, 2023

I have discovered that original System.Linq.Dynamic arround 2016 incorporate a security issue :
https://insinuator.net/2016/10/linq-injection-from-attacking-filters-to-code-execution/

Because i don't know how this product work, i would ask if such problem may affect also this tool, and if the answer is yes, which conter measure/mitigation may be adopted to prevent the issue.

Thanks for clarification.

@StefH StefH self-assigned this Feb 7, 2023
@StefH StefH added bug security and removed bug labels Feb 7, 2023
@JonathanMagnan
Copy link
Member

Hello @ItSkary ,

Sorry for the delay, and thank you for reporting this.

We are currently working on this issue and hope to release a new version shortly with a fix.

Best Regards,

Jon

@StefH
Copy link
Collaborator

StefH commented Mar 3, 2023

#669

@StefH StefH closed this as completed Mar 3, 2023
@StefH
Copy link
Collaborator

StefH commented Mar 3, 2023

Hello @ItSkary, a new version 1.3.0 will have this fix and will be released shorty.

@ItSkary
Copy link
Author

ItSkary commented Mar 15, 2023

Thanks a lot, i will update the package in my project ASAP

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Development

No branches or pull requests

3 participants