RUSTSEC-2020-0091
Dashboard / Vulnerabilities / RUSTSEC-2020-0091
RUSTSEC-2020-0091
Published: 10 Dec 2020Last Modified: 8 Nov 2023
Aliases:
Summary: Dangling reference in `access::Map` with Constant
Details: Using the `arc_swap::access::Map` with the `Constant` test helper (or with user-provided implementation of the `Access` trait) could sometimes lead to the map returning dangling references. Replaced by implementation without `unsafe`, at the cost of added `Clone` bound on the closure and small penalty on performance.
References: https://crates.io/crates/arc-swap, https://rustsec.org/advisories/RUSTSEC-2020-0091.html, https://github.com/vorner/arc-swap/issues/45
Affected packages
Package
Name: arc-swap
Purl: pkg:cargo/arc-swap
Affected ranges
Type: SEMVER
Events:
Introduced- 0.4.2
Fixed -0.4.8
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
