Описание
serde_yml crate is unsound and unmaintained
Using serde_yml::ser::Serializer.emitter can cause a segmentation fault, which is unsound.
The GitHub project for serde_yml was archived after unsoundness issues were raised.
If you rely on this crate, it is highly recommended switching to a maintained alternative.
Recommended alternatives
serde_norway- Maintained fork ofserde_yaml, usingunsafe-libyaml-norwayserde_yaml_ng- Maintained fork ofserde_yaml, using unmaintainedunsafe-libyaml
Incomplete pure Rust alternatives
These implementation do not rely on C libyaml.
Пакеты
Наименование
serde_yml
rust
Затронутые версииВерсия исправления
<= 0.0.12
Отсутствует
6.9 Medium
CVSS4
Дефекты
CWE-787
6.9 Medium
CVSS4
Дефекты
CWE-787