{"id":"GHSA-3w3h-7xgx-grwc","summary":"Leak in Aliyun  KeySecret ","details":"### Impact\nUsers of this library will be affected when using this library, the incoming secret will be disclosed unintentionally.\n\n### Patches\nThis have already been solved.\n\n### Workarounds\nNo, It cannot be patched without upgrading\n\n### References\nNo\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Email us at [email address](mailto:772364230@qq.com)\n","aliases":["CVE-2022-39397","RUSTSEC-2022-0089"],"modified":"2023-11-08T04:10:21.081461Z","published":"2022-11-21T20:39:05Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-11-21T20:39:05Z","nvd_published_at":"2022-11-22T21:15:00Z","cwe_ids":["CWE-200"]},"references":[{"type":"WEB","url":"https://github.com/tu6ge/oss-rs/security/advisories/GHSA-3w3h-7xgx-grwc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-39397"},{"type":"WEB","url":"https://github.com/tu6ge/oss-rs/commit/e4553f7d74fce682d802f8fb073943387796df29"},{"type":"PACKAGE","url":"https://github.com/tu6ge/oss-rs"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2022-0089.html"}],"affected":[{"package":{"name":"aliyun-oss-client","ecosystem":"crates.io","purl":"pkg:cargo/aliyun-oss-client"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.8.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-3w3h-7xgx-grwc/GHSA-3w3h-7xgx-grwc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:P/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N"}]}