Описание
An issue was discovered in the actix-web crate before 0.7.15 for Rust. It can unsoundly extend the lifetime of a string, leading to memory corruption.
Ссылки
- Third Party Advisory
- Issue TrackingThird Party Advisory
- Third Party Advisory
- Issue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.7.15 (исключая)
cpe:2.3:a:actix:actix-web:*:*:*:*:*:rust:*:*
EPSS
Процентиль: 58%
0.00363
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-787
Связанные уязвимости
CVSS3: 9.8
ubuntu
около 4 лет назад
An issue was discovered in the actix-web crate before 0.7.15 for Rust. It can unsoundly extend the lifetime of a string, leading to memory corruption.
EPSS
Процентиль: 58%
0.00363
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-787