Addressing RUSTSEC-2023-0029 #1002
christopinka
started this conversation in
General
Replies: 1 comment
-
|
@christopinka the nats crate mentioned in the header is unmaintained |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
cargo deny is giving me below report. Is there a plan for a fix?
error[vulnerability]: TLS certificate common name validation bypass ┌─ /home/ctopinka1/git-test/di-apps/Cargo.lock:167:1 │ 167 │ nats 0.24.0 registry+https://github.com/rust-lang/crates.io-index │ ----------------------------------------------------------------- security vulnerability detected │ = ID: RUSTSEC-2023-0029 = Advisory: https://rustsec.org/advisories/RUSTSEC-2023-0029 = The NATS official Rust clients are vulnerable to MitM when using TLS.
Beta Was this translation helpful? Give feedback.
All reactions