Hi there Miguel,A vulnerability was found in the recent version of the Forge Component CSV to JSON v1.0.1It uses / contains the .net file mysql.dll which contains a high vulnerability.https://nvd.nist.gov/vuln/detail/CVE-2024-0056Any chance a new version on the .net library can be implemented in your Forge Component?Thank you
Hi @Paul. ,
Another option is to clone this Forge component and update the library yourself instead of waiting for the Miguel to release a new version. If you need the fix right away, this is probably the fastest approach. Otherwise, you can wait for the component owner(Miguel) to publish the update.
Hope this helps,
Regards,
Manish Jawla
To avoid confusion, I mistyped the name of the library in the title.It would be the System.Data.SqlClient.dll that needs attention.
Rebuilding and compiling this component ourselves could be an option, but that would still leave the component vulnerable here on the Forge. Best for everyone is if this would be fixed here by the owner of this component.