CVE-2024-0056

Severity
8.7HIGH
EPSS
0.9%
top 24.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 9

Description

Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:NExploitability: 2.2 | Impact: 5.8

Affected Packages25 packages

CVEListV5microsoft/system.data.sqlclient1.04.8.6
NuGetSystem.Data.SqlClient< 4.8.6
NuGetMicrosoft.Data.SqlClient3.0.03.1.5+3
CVEListV5microsoft/microsoft.data.sqlclient2.02.1.7+3

Patches

🔴Vulnerability Details

3
GHSA
Microsoft.Data.SqlClient and System.Data.SqlClient vulnerable to SQL Data Provider Security Feature Bypass2024-01-09
OSV
Microsoft.Data.SqlClient and System.Data.SqlClient vulnerable to SQL Data Provider Security Feature Bypass2024-01-09
CVEList
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability2024-01-09

📋Vendor Advisories

2
Microsoft
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability2024-01-09
Red Hat
dotnet: Information Disclosure: MD.SqlClient(MDS) & System.data.SQLClient (SDS)2024-01-09