PT-2022-28249 · Unknown+1 · System.Configuration.Configurationmanager+2

Published

2022-11-22

·

Updated

2022-11-22

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Akka.NET versions prior to 1.4.46 Akka.NET versions prior to 1.5.0-alpha3
Description The issue is related to a remote code execution vulnerability in System.Common.Drawing v4.7.0, which is a dependency of the Akka module. The real-world impact of this issue is expected to be low.
Recommendations For versions prior to 1.4.46, upgrade to Akka.NET v1.4.46 or later. For versions prior to 1.5.0-alpha3, upgrade to Akka.NET v1.5.0-alpha3 or later. As a temporary workaround, consider explicitly referencing System.Configuration.ConfigurationManager's NuGet package and upgrading to 6.0.1 or later without upgrading Akka.NET, but it is recommended to upgrade Akka.NET itself for a more comprehensive solution.

Related Identifiers

GHSA-GPV5-RP6W-58R8

Affected Products

Akka.Net
System.Common.Drawing
System.Configuration.Configurationmanager