aliyun-oss-client is a rust client for Alibaba Cloud OSS. Users of this library will be affected, the incoming secret will be disclosed unintentionally. This issue has been patched in version 0.8.1.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://github.com/tu6ge/oss-rs/security/advisories/GHSA-3w3h-7xgx-grwc | third party advisory |
https://github.com/tu6ge/oss-rs/commit/e4553f7d74fce682d802f8fb073943387796df29 | third party advisory patch |