CVE-2024-0056

HIGH8.7EPSS 0.86%

Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability

Published: 1/9/2024Modified: 5/20/2025
Also known as:GHSA-98g6-xh36-x2p7BIT-dotnet-2024-0056BIT-dotnet-sdk-2024-0056

Description

Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability

Affected packages (4)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.7CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

References (3)