Microsoft.Diagnostics.Tracing.TraceEvent is vulnerable to Deserialization of Untrusted Data
71
High Risk
Affected versions of this package are vulnerable to deserialization of untrusted data, which allows the deserialization of unknown data types. This issue arises when the application does not properly validate or sanitize the data being deserialized. In the worst case, this vulnerability enables attackers to craft malicious input that, when deserialized, can lead to remote code execution (RCE).
You are affected if you are using a version that falls within the vulnerable range.
Microsoft.Diagnostics.Tracing.TraceEvent is vulnerable to Deserialization of Untrusted Data in versions 2.0.0 - 3.1.16.
Upgrade the Microsoft.Diagnostics.Tracing.TraceEvent library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant