{"id":"GHSA-xphf-cx8h-7q9g","summary":"`openssl` `X509StoreRef::objects` is unsound","details":"This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back.\n\nUse of this function should be replaced with `X509StoreRef::all_certificates`.\n","aliases":["RUSTSEC-2023-0072"],"modified":"2026-09-10T03:50:08.779469678Z","published":"2023-11-28T20:51:08Z","database_specific":{"nvd_published_at":null,"cwe_ids":[],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-11-28T20:51:08Z"},"references":[{"type":"WEB","url":"https://github.com/sfackler/rust-openssl/issues/2096"},{"type":"WEB","url":"https://github.com/sfackler/rust-openssl/commit/cf9681a55cabd4cb9f1475bde17b5079f2a0384e"},{"type":"PACKAGE","url":"https://github.com/sfackler/rust-openssl"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2023-0072.html"}],"affected":[{"package":{"name":"openssl","ecosystem":"crates.io","purl":"pkg:cargo/openssl"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.10.29"},{"fixed":"0.10.60"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-xphf-cx8h-7q9g/GHSA-xphf-cx8h-7q9g.json"}}],"schema_version":"1.9.0"}