-
Notifications
You must be signed in to change notification settings - Fork 57
Open
Labels
dependenciesPull requests that update a dependency filePull requests that update a dependency file
Description
Description
Zenoh crate introduces a vulnerability: eclipse-zenoh/zenoh#1687
The rsa crate tracking issue: RustCrypto/RSA#390
Crate: rsa
Version: 0.9.8
Title: Marvin Attack: potential key recovery through timing sidechannels
Date: 2023-11-22
ID: RUSTSEC-2023-0071
URL: https://rustsec.org/advisories/RUSTSEC-2023-0071
Severity: 5.9 (medium)
Solution: No fixed upgrade is available!
Dependency tree:
rsa 0.9.8
└── zenoh-transport 1.3.4
└── zenoh 1.3.4
└── cu-zenoh-sink 0.7.0
└── cu-zenoh 0.7.0
Actions
Track https://github.com/RustCrypto/RSA/tags to see if they release 0.9.9 and rustsec advisories remove the warning from their new version
Metadata
Metadata
Assignees
Labels
dependenciesPull requests that update a dependency filePull requests that update a dependency file