Логотип exploitDog
bind:CVE-2023-22466
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-22466

Количество 5

Количество 5

ubuntu логотип

CVE-2023-22466

около 3 лет назад

Tokio is a runtime for writing applications with Rust. Starting with version 1.7.0 and prior to versions 1.18.4, 1.20.3, and 1.23.1, when configuring a Windows named pipe server, setting `pipe_mode` will reset `reject_remote_clients` to `false`. If the application has previously configured `reject_remote_clients` to `true`, this effectively undoes the configuration. Remote clients may only access the named pipe if the named pipe's associated path is accessible via a publicly shared folder (SMB). Versions 1.23.1, 1.20.3, and 1.18.4 have been patched. The fix will also be present in all releases starting from version 1.24.0. Named pipes were introduced to Tokio in version 1.7.0, so releases older than 1.7.0 are not affected. As a workaround, ensure that `pipe_mode` is set first after initializing a `ServerOptions`.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2023-22466

около 3 лет назад

Tokio is a runtime for writing applications with Rust. Starting with version 1.7.0 and prior to versions 1.18.4, 1.20.3, and 1.23.1, when configuring a Windows named pipe server, setting `pipe_mode` will reset `reject_remote_clients` to `false`. If the application has previously configured `reject_remote_clients` to `true`, this effectively undoes the configuration. Remote clients may only access the named pipe if the named pipe's associated path is accessible via a publicly shared folder (SMB). Versions 1.23.1, 1.20.3, and 1.18.4 have been patched. The fix will also be present in all releases starting from version 1.24.0. Named pipes were introduced to Tokio in version 1.7.0, so releases older than 1.7.0 are not affected. As a workaround, ensure that `pipe_mode` is set first after initializing a `ServerOptions`.

CVSS3: 5.4
EPSS: Низкий
msrc логотип

CVE-2023-22466

около 3 лет назад

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2023-22466

около 3 лет назад

Tokio is a runtime for writing applications with Rust. Starting with v ...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-7rrj-xr53-82p7

около 3 лет назад

Tokio reject_remote_clients configuration may get dropped when creating a Windows named pipe

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-22466

Tokio is a runtime for writing applications with Rust. Starting with version 1.7.0 and prior to versions 1.18.4, 1.20.3, and 1.23.1, when configuring a Windows named pipe server, setting `pipe_mode` will reset `reject_remote_clients` to `false`. If the application has previously configured `reject_remote_clients` to `true`, this effectively undoes the configuration. Remote clients may only access the named pipe if the named pipe's associated path is accessible via a publicly shared folder (SMB). Versions 1.23.1, 1.20.3, and 1.18.4 have been patched. The fix will also be present in all releases starting from version 1.24.0. Named pipes were introduced to Tokio in version 1.7.0, so releases older than 1.7.0 are not affected. As a workaround, ensure that `pipe_mode` is set first after initializing a `ServerOptions`.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-22466

Tokio is a runtime for writing applications with Rust. Starting with version 1.7.0 and prior to versions 1.18.4, 1.20.3, and 1.23.1, when configuring a Windows named pipe server, setting `pipe_mode` will reset `reject_remote_clients` to `false`. If the application has previously configured `reject_remote_clients` to `true`, this effectively undoes the configuration. Remote clients may only access the named pipe if the named pipe's associated path is accessible via a publicly shared folder (SMB). Versions 1.23.1, 1.20.3, and 1.18.4 have been patched. The fix will also be present in all releases starting from version 1.24.0. Named pipes were introduced to Tokio in version 1.7.0, so releases older than 1.7.0 are not affected. As a workaround, ensure that `pipe_mode` is set first after initializing a `ServerOptions`.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
msrc логотип
CVSS3: 5.4
0%
Низкий
около 3 лет назад
debian логотип
CVE-2023-22466

Tokio is a runtime for writing applications with Rust. Starting with v ...

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-7rrj-xr53-82p7

Tokio reject_remote_clients configuration may get dropped when creating a Windows named pipe

CVSS3: 5.4
0%
Низкий
около 3 лет назад

Уязвимостей на страницу