CVE-2024-50353

ICG.AspNetCore.Utilities.CloudStorage is a collection of cloud storage utilities to assist with the management of files for cloud upload. Users of this library that set a duration for a SAS Uri with a value other than 1 hour may have generated a URL with a duration that is longer, or shorter than desired. Users not implemented SAS Uri's are unaffected. This issue was resolved in version 8.0.0 of the library.
Configurations

Configuration 1 (hide)

cpe:2.3:a:iowacomputergurus:aspnetcore.utilities.cloudstorage:*:*:*:*:*:*:*:*

History

13 Nov 2024, 15:15

Type Values Removed Values Added
First Time Iowacomputergurus
Iowacomputergurus aspnetcore.utilities.cloudstorage
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:iowacomputergurus:aspnetcore.utilities.cloudstorage:*:*:*:*:*:*:*:*
References () https://github.com/IowaComputerGurus/aspnetcore.utilities.cloudstorage/commit/8ea534481181a063175f457082662fdcad9a41ff - () https://github.com/IowaComputerGurus/aspnetcore.utilities.cloudstorage/commit/8ea534481181a063175f457082662fdcad9a41ff - Patch
References () https://github.com/IowaComputerGurus/aspnetcore.utilities.cloudstorage/security/advisories/GHSA-24mc-gc52-47jv - () https://github.com/IowaComputerGurus/aspnetcore.utilities.cloudstorage/security/advisories/GHSA-24mc-gc52-47jv - Vendor Advisory

01 Nov 2024, 12:57

Type Values Removed Values Added
Summary
  • (es) ICG.AspNetCore.Utilities.CloudStorage es una colección de utilidades de almacenamiento en la nube que ayudan con la administración de archivos para la carga en la nube. Los usuarios de esta librería que configuran una duración para una URL de SAS con un valor distinto de 1 hora pueden haber generado una URL con una duración mayor o menor a la deseada. Los usuarios que no implementaron URL de SAS no se ven afectados. Este problema se resolvió en la versión 8.0.0 de la librería.

30 Oct 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-30 14:15

Updated : 2024-11-13 15:15


NVD link : CVE-2024-50353

Mitre link : CVE-2024-50353

CVE.ORG link : CVE-2024-50353


JSON object : View

Products Affected

iowacomputergurus

  • aspnetcore.utilities.cloudstorage
CWE
NVD-CWE-noinfo CWE-284

Improper Access Control