Description
aliyun-oss-client is a rust client for Alibaba Cloud OSS. Users of this library will be affected, the incoming secret will be disclosed unintentionally. This issue has been patched in version 0.8.1.
References
https://github.com/tu6ge/oss-rs/commit/e4553f7d74fce682d802f8fb073943387796df29
PatchThird Party Advisory
https://github.com/tu6ge/oss-rs/security/advisories/GHSA-3w3h-7xgx-grwc
Third Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
4.3 · Medium
CVSS V3.1
CVSS V3.0
CVSS V2.0
Information
Source identifier
Vulnerability status
Analyzed
Published
2022-11-22T21:15:10.737
2 years agoLast modified
2023-07-11T20:41:50.193
2 years ago