Skip to content

Wrong unaffected in CVE #1813

Closed
Closed
@pinkforest

Description

@pinkforest

Hi @asomers

Re old CVE:

RustSec original thread(s) - these are fine it's just CVE that needs a minor fix:

Expected Affected / Patched Matrix

It should be across CVE, GHSA and RustSec databases:

Affected versions Patched versions
>= 0.16.0, < 0.20.2 0.20.2
>= 0.21.0, < 0.21.2 0.21.2
>= 0.22.0, < 0.22.2 0.22.2

Problem

It seems that the nist CVE has got wrong unaffected for the 0.20 series so basically anything below 0.20.0 is seemingly affected

Dependabot is screaming at me if using old 0.13.0 version which is supposed to be unaffected

Dependabot via GHSA uses both CVE and GHSA advisories held in GHSA

Fix

Needs ot be fixed so < 0.16.0 are unaffected per RUSTSEC / GHSA non-CVE derived:

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions