Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3w3h-7xgx-grwc

Опубликовано: 21 нояб. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.6

Описание

Leak in Aliyun KeySecret

Impact

Users of this library will be affected when using this library, the incoming secret will be disclosed unintentionally.

Patches

This have already been solved.

Workarounds

No, It cannot be patched without upgrading

References

No

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

aliyun-oss-client

rust
Затронутые версииВерсия исправления

< 0.8.1

0.8.1

EPSS

Процентиль: 54%
0.00314
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.6
nvd
около 3 лет назад

aliyun-oss-client is a rust client for Alibaba Cloud OSS. Users of this library will be affected, the incoming secret will be disclosed unintentionally. This issue has been patched in version 0.8.1.

EPSS

Процентиль: 54%
0.00314
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-200