Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 908820 - dev-dotnet/dotnet-sdk-bin: nuget credential leakage
Summary: dev-dotnet/dotnet-sdk-bin: nuget credential leakage
Status: CONFIRMED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://github.com/NuGet/Home/issues/...
Whiteboard: B4 [ebuild]
Keywords:
Depends on:
Blocks: CVE-2022-30184
  Show dependency tree
 
Reported: 2023-06-19 03:02 UTC by John Helmert III
Modified: 2023-06-19 18:29 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-06-19 03:02:16 UTC
CVE-2022-30184 (https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-30184):

.NET and Visual Studio Information Disclosure Vulnerability.
Comment 1 Larry the Git Cow gentoo-dev 2023-06-19 18:29:37 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=1f9f7f85b21b773952028a92ee1a3a6f0a79f1ea

commit 1f9f7f85b21b773952028a92ee1a3a6f0a79f1ea
Author:     Maciej Barć <xgqt@gentoo.org>
AuthorDate: 2023-06-19 18:17:41 +0000
Commit:     Maciej Barć <xgqt@gentoo.org>
CommitDate: 2023-06-19 18:29:33 +0000

    dev-dotnet/dotnet-sdk-bin: drop old 5.0.408-r4
    
    Bug: https://bugs.gentoo.org/908819
    Bug: https://bugs.gentoo.org/908820
    Signed-off-by: Maciej Barć <xgqt@gentoo.org>

 dev-dotnet/dotnet-sdk-bin/Manifest                 |  6 ---
 .../dotnet-sdk-bin-5.0.408-r4.ebuild               | 62 ----------------------
 2 files changed, 68 deletions(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=2dc4834fe52b3630a2f161326a17c50c7576b52c

commit 2dc4834fe52b3630a2f161326a17c50c7576b52c
Author:     Maciej Barć <xgqt@gentoo.org>
AuthorDate: 2023-06-19 18:17:28 +0000
Commit:     Maciej Barć <xgqt@gentoo.org>
CommitDate: 2023-06-19 18:29:33 +0000

    dev-dotnet/dotnet-sdk-bin: drop old 3.1.423-r4
    
    Bug: https://bugs.gentoo.org/908819
    Bug: https://bugs.gentoo.org/908820
    Signed-off-by: Maciej Barć <xgqt@gentoo.org>

 dev-dotnet/dotnet-sdk-bin/Manifest                 |  4 --
 .../dotnet-sdk-bin-3.1.423-r4.ebuild               | 60 ----------------------
 2 files changed, 64 deletions(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=4e175c11278e2d3f9ad831a6503ca10ef5ecbc2d

commit 4e175c11278e2d3f9ad831a6503ca10ef5ecbc2d
Author:     Maciej Barć <xgqt@gentoo.org>
AuthorDate: 2023-06-19 18:17:06 +0000
Commit:     Maciej Barć <xgqt@gentoo.org>
CommitDate: 2023-06-19 18:29:33 +0000

    virtual/dotnet-sdk: drop old 5.0-r1
    
    Bug: https://bugs.gentoo.org/908819
    Bug: https://bugs.gentoo.org/908820
    Signed-off-by: Maciej Barć <xgqt@gentoo.org>

 virtual/dotnet-sdk/dotnet-sdk-5.0-r1.ebuild | 16 ----------------
 1 file changed, 16 deletions(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=86154485655909d831f0270354f5e22b328c793e

commit 86154485655909d831f0270354f5e22b328c793e
Author:     Maciej Barć <xgqt@gentoo.org>
AuthorDate: 2023-06-19 18:16:19 +0000
Commit:     Maciej Barć <xgqt@gentoo.org>
CommitDate: 2023-06-19 18:29:32 +0000

    virtual/dotnet-sdk: drop old 3.1-r1
    
    Bug: https://bugs.gentoo.org/908819
    Bug: https://bugs.gentoo.org/908820
    Signed-off-by: Maciej Barć <xgqt@gentoo.org>

 virtual/dotnet-sdk/dotnet-sdk-3.1-r1.ebuild | 16 ----------------
 1 file changed, 16 deletions(-)