Skip to content

Update Hangfire.Core to 1.8.20 to fix CVE-2024-21907 #4616

@DanielMcAssey

Description

@DanielMcAssey

Package

Sentry.Hangfire

.NET Flavor

.NET

.NET Version

9.0.7

OS

Any (not platform specific)

OS Version

No response

Development Environment

Visual Studio v17.x

SDK Version

5.16.0

Self-Hosted Sentry Version

No response

Workload Versions

Hangfire.Core is affected by CVE-2024-21907 through their Newtonsoft.Json dependency, it has been fixed in later Hangfire.Core versions, such as 1.18.20

UseSentry or SentrySdk.Init call

N/A

Steps to Reproduce

N/A

Expected Result

Non-vulnerable version

Actual Result

Vulnerable version

Metadata

Metadata

Assignees

Labels

.NETPull requests that update .net codeBugSomething isn't working

Projects

Status

No status

Status

No status

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions