CVE-2024-21319
Description
Important: .NET 6.0 security update
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2024-0156.html
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2024-0152.html
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2024-0151.html
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2024-0158.html
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2024:0158
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2024-0157.html
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2024:0157
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2024-0150.html
Vendor advisory: alma — https://bugzilla.redhat.com/2257566
Vendor advisory: alma — https://bugzilla.redhat.com/2255386
Vendor advisory: alma — https://bugzilla.redhat.com/2255384
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2024:0150
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:0157
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:0150
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:0158
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:0156
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:0152
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:0151
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| rhel | 9 | fixed | |
| rocky | 8 | fixed | |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| NuGet | System.IdentityModel.Tokens.Jwt | <5.7.0 | 5.7.0 |
| NuGet | System.IdentityModel.Tokens.Jwt | >=6.5.0,<6.34.0 | 6.34.0 |
| NuGet | System.IdentityModel.Tokens.Jwt | >=7.0.0-preview,<7.1.2 | 7.1.2 |
| NuGet | Microsoft.IdentityModel.JsonWebTokens | <5.7.0 | 5.7.0 |
| NuGet | Microsoft.IdentityModel.JsonWebTokens | >=6.5.0,<6.34.0 | 6.34.0 |
| NuGet | Microsoft.IdentityModel.JsonWebTokens | >=7.0.0-preview,<7.1.2 | 7.1.2 |
References
- https://access.redhat.com/errata/RHSA-2024:0151
- https://access.redhat.com/errata/RHSA-2024:0152
- https://access.redhat.com/errata/RHSA-2024:0156
- https://errata.rockylinux.org/RLSA-2024:0158
- https://errata.rockylinux.org/RLSA-2024:0150
- https://errata.rockylinux.org/RLSA-2024:0157
- https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/security/advisories/GHSA-8g9c-28fc-mcx2
- https://github.com/dotnet/aspnetcore/security/advisories/GHSA-59j7-ghrg-fj52
- https://github.com/dotnet/announcements/issues/290
- https://github.com/dotnet/aspnetcore
- https://access.redhat.com/errata/RHSA-2024:0150
- https://bugzilla.redhat.com/2255384
- https://bugzilla.redhat.com/2255386
- https://bugzilla.redhat.com/2257566
- https://errata.almalinux.org/8/ALSA-2024-0150.html
- https://access.redhat.com/errata/RHSA-2024:0157
- https://errata.almalinux.org/8/ALSA-2024-0157.html
- https://access.redhat.com/errata/RHSA-2024:0158
- https://errata.almalinux.org/8/ALSA-2024-0158.html
- https://errata.almalinux.org/9/ALSA-2024-0151.html
- https://errata.almalinux.org/9/ALSA-2024-0152.html
- https://errata.almalinux.org/9/ALSA-2024-0156.html
Verify integrity in audit chain (admin only). AS-IS.