MEDIUM5.6
GHSA-3w3h-7xgx-grwc
Leak in Aliyun KeySecret
Details
### Impact Users of this library will be affected when using this library, the incoming secret will be disclosed unintentionally.
### Patches This have already been solved.
### Workarounds No, It cannot be patched without upgrading
### References No
### For more information If you have any questions or comments about this advisory: * Email us at [email address](mailto:772364230@qq.com)
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/aliyun-oss-client
Introduced in:
0Fixed in: 0.8.1Upgrade aliyun-oss-client to 0.8.1 or newer (ecosystem crates.io).
References
- https://github.com/tu6ge/oss-rs/security/advisories/GHSA-3w3h-7xgx-grwc[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2022-39397[ADVISORY]
- https://github.com/tu6ge/oss-rs/commit/e4553f7d74fce682d802f8fb073943387796df29[WEB]
- https://github.com/tu6ge/oss-rs[PACKAGE]
- https://rustsec.org/advisories/RUSTSEC-2022-0089.html[WEB]