{"id":"GHSA-3gxf-9r58-2ghg","summary":"`openssl` `X509NameBuilder::build` returned object is not thread safe","details":"OpenSSL has a `modified` bit that it can set on on `X509_NAME` objects. If this bit is set then the object is not thread-safe even when it appears the code is not modifying the value.\n\nThanks to David Benjamin (Google) for reporting this issue.\n","aliases":["RUSTSEC-2023-0022"],"modified":"2023-11-08T04:14:38.793551Z","published":"2023-03-24T22:01:35Z","database_specific":{"nvd_published_at":null,"cwe_ids":[],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-03-24T22:01:35Z"},"references":[{"type":"WEB","url":"https://github.com/sfackler/rust-openssl/pull/1854"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2023-0022.html"}],"affected":[{"package":{"name":"openssl","ecosystem":"crates.io","purl":"pkg:cargo/openssl"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.9.7"},{"fixed":"0.10.48"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/03/GHSA-3gxf-9r58-2ghg/GHSA-3gxf-9r58-2ghg.json"}}],"schema_version":"1.9.0"}