Skip to main content
Question

Vulnerability for Microsoft .NET 8.0


Forum|alt.badge.img+1

Hello, 

one of my customers is running CV 11.32.89 and .Net 8.0.406. Their Security Team discovered vulnerability in the current .Net version and advised to update to .NET_9.0_SDK_(v9.0.200)_x64. However, in the Commvault KB I see, that manual DotNet updates to another major version (e.g. 8->9) are generally not allowed:
Manual Upgrade of .NET Core Runtime

Could you please advise how the customer can proceed to handle the vulnerability?

Best regards, 

Aleksandra 

4 replies

Jon Vengust
Vaulter
Forum|alt.badge.img+5
  • Vaulter
  • 17 replies
  • March 19, 2025

Hi Aleksandra,

 

Hope you’re doing well.

 

What is the specific vulnerability affecting the customer’s .NET Core 8.0.x deployment? EOS for 8.0.x is slated for November 2026 so I would assume a patch/workaround should be available for the current major release.

 

You are correct in that with Commvault 11.32 .NET 9.x is not supported. Only 8.0.x configurations are certified and we cannot guarantee functionality if an upgrade to 9.x were to be performed.


Forum|alt.badge.img+1
  • Author
  • Bit
  • 2 replies
  • March 19, 2025

Hello Jon, 

 

thank you very much for your detailed reply. 

The customer did not inform about the exact vulnerability he discovered. 

However, he is asking now, what would be the highest release of .NET 8.0.x version that they can safely update to.

Could you please advise on that?

Best regards, 

Aleksandra


Jon Vengust
Vaulter
Forum|alt.badge.img+5
  • Vaulter
  • 17 replies
  • March 19, 2025

All minor versions of .NET 8.0.x are supported.

 

Update to the latest minor version of 8.0.x if that means the vulnerability has been included within a recent patch.


Forum|alt.badge.img+1
  • Author
  • Bit
  • 2 replies
  • March 21, 2025

Hello Jon, 

 

thank you very much for your support. 

The issue has been resolved.

 

Best regards,

Aleksandra


Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings