RUSTSEC-2021-0077

    Dashboard / Vulnerabilities / RUSTSEC-2021-0077

    RUSTSEC-2021-0077

    Published: 22 Jul 2021Last Modified: 8 Nov 2023

    Summary: `better-macro` has deliberate RCE to prove a point

    Details: [better-macro](https://crates.io/crates/better-macro) is a fake crate which is "Proving A Point" that proc-macros can run arbitrary code. This is not a particularly novel or interesting observation. It currently opens `https://github.com/raycar5/better-macro/blob/master/doc/hi.md` which doesn't appear to have any malicious content, but there's no guarantee that will remain the case. This crate has no useful functionality, and should not be used.

    Affected packages

    Package

    Name: better-macro

    Purl: pkg:cargo/better-macro

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.0.0-0
    Fixed -None

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    RUSTSEC-2021-0077 | CVE-DB