MEDIUM
Exposure of sensitive information in aliyun-oss-client
Published Nov 22, 2022
5.6
MEDIUMCVSS 3.1
EPSS 0.46%
Description
aliyun-oss-client is a rust client for Alibaba Cloud OSS. Users of this library will be affected, the incoming secret will be disclosed unintentionally. This issue has been patched in version 0.8.1.
Affected products
-
- Version < 0.8.1StatusaffectedConstraints-
- Version
- < 0.8.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-7215 Advisory
- https://github.com/advisories/GHSA-3w3h-7xgx-grwc Advisory
- https://github.com/tu6ge/oss-rs/commit/e4553f7d74fce682d802f8fb073943387796df29 PatchThird Party Advisory
- https://github.com/tu6ge/oss-rs/security/advisories/GHSA-3w3h-7xgx-grwc Third Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-39397
- https://rustsec.org/advisories/RUSTSEC-2022-0089.html
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Nov 22, 2022
Updated Apr 23, 2025
Reserved Sep 2, 2022
Link CVE-2022-39397
CISA Vulnrichment
Updated Apr 23, 2025
ENISA EUVD
EUVD-2022-7215 GHSA-3W3H-7XGX-GRWC Assigner GitHub_M
Published Nov 22, 2022
Updated Apr 23, 2025
Exploited since n/a
Link EUVD-2022-7215