Описание
An issue was discovered in the better-macro crate through 2021-07-22 for Rust. It intentionally demonstrates that remote attackers can execute arbitrary code via proc-macros, and otherwise has no legitimate purpose.
Ссылки
- Third Party Advisory
- ExploitIssue TrackingPatchThird Party Advisory
- Third Party Advisory
- ExploitIssue TrackingPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2021-07-22 (включая)
cpe:2.3:a:better-macro_project:better-macro:*:*:*:*:*:rust:*:*
EPSS
Процентиль: 87%
0.03365
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-94
Связанные уязвимости
EPSS
Процентиль: 87%
0.03365
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-94