This project contains known security vulnerabilities. Find detailed information at the bottom.

Crate javelin

Dependencies

(19 total, 12 outdated, 1 insecure)

CrateRequiredLatestStatus
 bytes^0.41.12.1out of date
 chrono^0.40.4.45up to date
 clap~2.324.6.7out of date
 futures^0.10.3.34out of date
 javelin-codec^0.3.40.3.4up to date
 log^0.40.4.34up to date
 m3u8-rs^1.06.0.1out of date
 mpeg2ts^0.10.6.1out of date
 native-tls^0.20.2.18up to date
 parking_lot^0.70.12.5out of date
 rml_rtmp^0.20.8.0out of date
 serde^1.01.0.229up to date
 serde_json^1.01.0.151up to date
 serde_yaml^0.80.9.34+deprecatedout of date
 simplelog^0.50.12.2out of date
 tempfile^3.03.27.0up to date
 tokio^0.11.53.1out of date
 tokio-tls^0.20.3.1out of date
 warp ⚠️^0.10.4.3insecure

Security Vulnerabilities

warp: Improper validation of Windows paths could lead to directory traversal attack

RUSTSEC-2022-0082

Path resolution in warp::filters::fs::dir didn't correctly validate Windows paths meaning paths like /foo/bar/c:/windows/web/screen/img101.png would be allowed and respond with the contents of c:/windows/web/screen/img101.png. Thus users could potentially read files anywhere on the filesystem.

This only impacts Windows. Linux and other unix likes are not impacted by this.