YARP Denial of Service Vulnerability
High severity
GitHub Reviewed
Published
Jun 22, 2023
in
microsoft/reverse-proxy
•
Updated Jun 3, 2024
Description
Published by the National Vulnerability Database
Jun 23, 2023
Published to the GitHub Advisory Database
Jun 23, 2023
Reviewed
Jun 23, 2023
Last updated
Jun 3, 2024
Impact
A denial of service vulnerability exists in YARP.
Patches
If you're using YARP 1.x, you should update to NuGet package version 1.1.2.
If you're using YARP 2.0.0, you should update to NuGet package version 2.0.1.
You can do so by updating the
PackageReference
in your.csproj
fileor by selecting
2.0.1
in the NuGet UI inside Visual Studio (Manage NuGet Packages
/Updates
)References
CVE-2023-33141
References