Skip to content

Track rsa crate version in zenoh_transport #314

@makeecat

Description

@makeecat

Description

Zenoh crate introduces a vulnerability: eclipse-zenoh/zenoh#1687
The rsa crate tracking issue: RustCrypto/RSA#390

Crate: rsa
Version: 0.9.8
Title: Marvin Attack: potential key recovery through timing sidechannels
Date: 2023-11-22
ID: RUSTSEC-2023-0071
URL: https://rustsec.org/advisories/RUSTSEC-2023-0071
Severity: 5.9 (medium)
Solution: No fixed upgrade is available!
Dependency tree:
rsa 0.9.8
└── zenoh-transport 1.3.4
└── zenoh 1.3.4
└── cu-zenoh-sink 0.7.0
└── cu-zenoh 0.7.0

Actions

Track https://github.com/RustCrypto/RSA/tags to see if they release 0.9.9 and rustsec advisories remove the warning from their new version

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependenciesPull requests that update a dependency file

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions