Skip to content

Race Condition Enabling Link Following and Time-of-check Time-of-use (TOCTOU) Race Condition in remove_dir_all

Low
SteveLauC published GHSA-f2wx-xjfw-xjv6 Jul 15, 2023

Package

cargo topgrade (Rust)

Affected versions

<= 12.0.0

Patched versions

>= 12.0.1

Description

Summary

GHSA-mc8h-8q98-g5hr
XAMPPRocky/remove_dir_all@7247a8b

tempfile v0.4.26 ships with affected remove_dir_all v0.5.3 and so blocks my deployment of v12 to openSUSE distribution because it imposes a clean cargo audit

Updating tempfile is warranted

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs

Credits