---
title: Security Bulletin NR19-01
source: https://docs.newrelic.com/docs/security/new-relic-security/security-bulletins/security-bulletin-nr19-01
---

## Summary

A security update for the .NET agent corrects an issue where query strings may be captured when using OpenRasta instrumentation.

**Release date:** January 9, 2019

**Vulnerability identifier:** NR19-01

**Priority:** Medium

## Affected software [#affected]

The following New Relic agent versions are affected:

| Name       | Affected version | Notes | Remediated version |
| ---------- | ---------------- | ----- | ------------------ |
| .NET agent | &lt;8.12.216.0   |       | 8.12.216.0         |

## Vulnerability information [#vuln-info]

When using OpenRasta instrumentation, the full URL may be captured on instrumented requests. This may result in query strings being collected which can contain sensitive information

### Mitigating factors [#factors]

This vulnerability only exists when using OpenRasta instrumentation.

## Workarounds

-   [Update to the latest New Relic .NET agent.](https://docs.newrelic.com/docs/agents/net-agent/installation/update-net-agent)
-   Disable OpenRasta instrumentation.

## Report security vulnerabilities to New Relic [#report]

New Relic is committed to the security of our customers and their data. If you believe you have found a security vulnerability in one of our products or websites, we welcome and greatly appreciate you reporting it to New Relic's coordinated disclosure program. For more information, see [Reporting security vulnerabilities](https://docs.newrelic.com/docs/security/new-relic-security/data-privacy/reporting-security-vulnerabilities).
