RUSTSEC-2022-0071
Dashboard / Vulnerabilities / RUSTSEC-2022-0071
RUSTSEC-2022-0071
Published: 24 Apr 2022Last Modified: 18 Dec 2022
Summary: Rusoto is unmaintained
Details: The maintainers of Rusoto advise that all its crates are deprecated. This includes the common crates `rusoto_core`, `rusoto_signature`, `rusoto_credential`, and service crates such as `rusoto_s3` and `rusoto_ec2`. Users should migrate to the [AWS SDK for Rust](https://github.com/awslabs/aws-sdk-rust), which is maintained by AWS.
References: https://crates.io/crates/rusoto_credential, https://rustsec.org/advisories/RUSTSEC-2022-0071.html, https://github.com/rusoto/rusoto/issues/1651
Affected packages
Package
Name: rusoto_credential
Purl: pkg:cargo/rusoto_credential
Affected ranges
Type: SEMVER
Events:
Introduced- 0.0.0-0
Fixed -None
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
