Description
aliyun-oss-client is a rust client for Alibaba Cloud OSS. Users of this library will be affected, the incoming secret will be disclosed unintentionally. This issue has been patched in version 0.8.1.
References
https://github.com/tu6ge/oss-rs/commit/e4553f7d74fce682d802f8fb073943387796df29
PatchThird Party Advisory
https://github.com/tu6ge/oss-rs/security/advisories/GHSA-3w3h-7xgx-grwc
Third Party Advisory
https://github.com/tu6ge/oss-rs/commit/e4553f7d74fce682d802f8fb073943387796df29
PatchThird Party Advisory
https://github.com/tu6ge/oss-rs/security/advisories/GHSA-3w3h-7xgx-grwc
Third Party Advisory
CVSS impact metrics
CVSS:3.1/AV:P/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N
5.6 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2022-11-22T20:15:10.737Z
3 years agoLast modified
2024-11-21T06:18:12.503Z
1 year ago