Описание
cassandra-rs is a Cassandra (CQL) driver for Rust. Code that attempts to use an item (e.g., a row) returned by an iterator after the iterator has advanced to the next item will be accessing freed memory and experience undefined behaviour. The problem has been fixed in version 3.0.0.
Ссылки
- Patch
- Vendor Advisory
- Patch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.0.0 (исключая)
cpe:2.3:a:cassandra-rs_project:cassandra-rs:*:*:*:*:*:rust:*:*
EPSS
Процентиль: 58%
0.0037
Низкий
7.5 High
CVSS3
Дефекты
CWE-416
CWE-416
Связанные уязвимости
CVSS3: 7.5
github
почти 2 года назад
cassandra-rs's non-idiomatic use of iterators leads to use after free
EPSS
Процентиль: 58%
0.0037
Низкий
7.5 High
CVSS3
Дефекты
CWE-416
CWE-416