RUSTSEC-2020-0166

    Dashboard / Vulnerabilities / RUSTSEC-2020-0166

    RUSTSEC-2020-0166

    Published: 4 Sept 2020Last Modified: 8 Nov 2023

    Summary: personnummer Input validation error

    Details: Swedish personal identity is in the form of YYMMDD-XXXX An issue arises from the regular expression allowing the first three digits in the last four digits of the personnummer to be 000, which is invalid. To mitigate this without upgrading, a check on the last four digits can be made to make sure it's not 000x. The affected version should not be relied on without the mitigation to check that the swedish personal identity number is valid.

    Affected packages

    Package

    Name: personnummer

    Purl: pkg:cargo/personnummer

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.0.0-0
    Fixed -3.0.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    RUSTSEC-2020-0166 | CVE-DB