-
Notifications
You must be signed in to change notification settings - Fork 51
CVE-2020-26235 advisory for indirect time 0.1 dependency #306
Copy link
Copy link
Closed
Labels
SecurityPublicly Connected to SecurityPublicly Connected to Security
Description
We use the chrono package, which uses the time package. The time package has a vulnerability.
Vulnerabilities: GHSA-wcg3-cvx6-7396
Latest version: https://crates.io/crates/chrono (0.4.24)
Time 0.1.45 is deprecated: https://crates.io/crates/time/0.1.45
They (chrono) plan to release a new version, but the vulnerability was reported on Nov 18, 2020.
More info:
- Latest release
0.4.24usestime:0.1.45which has some vulnerabilities chronotope/chrono#1015 - CVE-2020-26235 advisory for time 0.1 dependency chronotope/chrono#602
Maybe we could try to disable some features to remove the dependency with the vulnerability.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
SecurityPublicly Connected to SecurityPublicly Connected to Security
Type
Projects
Status
No status