GHSA-frcx-xc72-c4v4

Suggest an improvement
Source
https://github.com/advisories/GHSA-frcx-xc72-c4v4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/11/GHSA-frcx-xc72-c4v4/GHSA-frcx-xc72-c4v4.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-frcx-xc72-c4v4
Aliases
Withdrawn
2021-11-30T21:33:03Z
Published
2021-11-29T18:09:08Z
Modified
2026-09-10T03:49:09Z
Severity
  • 3.1 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Use of Sha-1 in tusdotnet
Details

Withdrawn

After reviewing this CVE, we have withdrawn this advisory due to it not having actual security impact.

Original Advisory

The client in tusdotnet through 2.5.0 relies on SHA-1 to prevent spoofing of file content.

Database specific
{
    "cwe_ids":  [
        "CWE-327"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2021-11-23T19:18:34Z",
    "nvd_published_at":  "2021-11-22T22:15:00Z",
    "severity":  "LOW"
}
References

Affected packages

NuGet / tusdotnet

Package

Name
tusdotnet
View open source insights on deps.dev
Purl
pkg:nuget/tusdotnet

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2.5.0

Affected versions

1.*
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
2.*
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.5.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/11/GHSA-frcx-xc72-c4v4/GHSA-frcx-xc72-c4v4.json"