{"id":"GHSA-w65q-jcmv-28gj","summary":"Dynamic Linq vulnerable to remote code execution","details":"Dynamic Linq 1.0.7.10 through 1.2.25 before 1.3.0 allows attackers to execute arbitrary code and commands when untrusted input to methods including Where, Select, OrderBy is parsed.","aliases":["CVE-2023-32571"],"modified":"2024-02-21T05:32:21.968258Z","published":"2023-06-22T21:30:49Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-06-23T21:38:13Z","nvd_published_at":"2023-06-22T20:15:09Z","cwe_ids":["CWE-697"],"severity":"CRITICAL"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-32571"},{"type":"PACKAGE","url":"https://github.com/zzzprojects/System.Linq.Dynamic.Core"},{"type":"WEB","url":"https://research.nccgroup.com/2023/06/13/dynamic-linq-injection-remote-code-execution-vulnerability-cve-2023-32571"}],"affected":[{"package":{"name":"System.Linq.Dynamic.Core","ecosystem":"NuGet","purl":"pkg:nuget/System.Linq.Dynamic.Core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.7.10"},{"fixed":"1.3.0"}]}],"versions":["1.0.10","1.0.11","1.0.12","1.0.13","1.0.14","1.0.15","1.0.16","1.0.17","1.0.18","1.0.19","1.0.20","1.0.21","1.0.22","1.0.23","1.0.24","1.0.7.10","1.0.7.11","1.0.7.12","1.0.7.13","1.0.8","1.0.8.1","1.0.8.10","1.0.8.11","1.0.8.12","1.0.8.13","1.0.8.14","1.0.8.15","1.0.8.16","1.0.8.17","1.0.8.18","1.0.8.2","1.0.8.3","1.0.8.4","1.0.8.5","1.0.8.6","1.0.8.7","1.0.8.8","1.0.8.9","1.0.9","1.0.9.1","1.0.9.2","1.1.0","1.1.1","1.1.2","1.1.3","1.1.4","1.1.5","1.1.6","1.1.7","1.1.8","1.2.0","1.2.1","1.2.10","1.2.11","1.2.12","1.2.13","1.2.14","1.2.15","1.2.16","1.2.17","1.2.18","1.2.19","1.2.2","1.2.20","1.2.20-preview-01","1.2.21","1.2.22","1.2.23","1.2.24","1.2.25","1.2.3","1.2.4","1.2.5","1.2.6","1.2.6-preview-01","1.2.7","1.2.7-preview-01","1.2.7-preview-02","1.2.7-preview-03","1.2.8","1.2.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-w65q-jcmv-28gj/GHSA-w65q-jcmv-28gj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}