Critical severityNVD Advisory· Published Jun 22, 2023· Updated Dec 6, 2024
CVE-2023-32571
CVE-2023-32571
Description
Dynamic Linq 1.0.7.10 through 1.2.25 before 1.3.0 allows attackers to execute arbitrary code and commands when untrusted input to methods including Where, Select, OrderBy is parsed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
System.Linq.Dynamic.CoreNuGet | >= 1.0.7.10, < 1.3.0 | 1.3.0 |
Affected products
2- Dynamic Linq/Dynamic Linqdescription
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-w65q-jcmv-28gjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-32571ghsaADVISORY
- research.nccgroup.com/2023/06/13/dynamic-linq-injection-remote-code-execution-vulnerability-cve-2023-32571ghsaWEB
- research.nccgroup.com/2023/06/13/dynamic-linq-injection-remote-code-execution-vulnerability-cve-2023-32571/mitre
News mentions
0No linked articles in our index yet.