This project might be open to known security vulnerabilities, which can be prevented by tightening the version range of affected dependencies. Find detailed information at the bottom.

Crate exonum-cryptocurrency-advanced

Dependencies

(7 total, 4 outdated, 1 possibly insecure)

CrateRequiredLatestStatus
 exonum^0.11.01.0.0out of date
 exonum-configuration^0.11.00.12.0out of date
 exonum-derive^0.11.01.0.0out of date
 failure^0.1.50.1.8up to date
 protobuf ⚠️^2.4.03.4.0out of date
 serde^1.0.01.0.198up to date
 serde_derive^1.0.01.0.198up to date

Dev dependencies

(5 total, 3 outdated)

CrateRequiredLatestStatus
 assert_matches^1.2.01.5.0up to date
 exonum-testkit^0.11.01.0.0out of date
 hex^0.3.20.4.3out of date
 pretty_assertions^0.6.11.4.0out of date
 serde_json^1.0.01.0.116up to date

Security Vulnerabilities

protobuf: Out of Memory in stream::read_raw_bytes_into()

RUSTSEC-2019-0003

Affected versions of this crate called Vec::reserve() on user-supplied input.

This allows an attacker to cause an Out of Memory condition while calling the vulnerable method on untrusted data.