This project contains known security vulnerabilities. Find detailed information at the bottom.

Crate toxicblend

Dependencies

(19 total, 18 outdated, 1 insecure)

CrateRequiredLatestStatus
 ahash~0.70.8.12out of date
 boostvoronoi~0.100.12.1out of date
 bytemuck~1.71.25.2out of date
 centerline~0.70.14.0out of date
 cgmath~0.180.18.0up to date
 fast-surface-nets~0.10.2.1out of date
 ilattice~0.10.4.0out of date
 itertools~0.100.15.0out of date
 linestring~0.80.16.0out of date
 logos~0.120.16.1out of date
 macaw~0.150.30.0out of date
 prost~0.90.14.4out of date
 rayon~1.51.12.0out of date
 saft~0.270.34.1out of date
 smallvec~1.71.16.1out of date
 thiserror~1.02.0.21out of date
 tokio ⚠️~1.151.53.1insecure
 tonic~0.60.14.6out of date
 vob~3.04.0.1out of date

Dev dependencies

(1 total, 1 outdated)

CrateRequiredLatestStatus
 criterion~0.30.8.2out of date

Security Vulnerabilities

tokio: reject_remote_clients Configuration corruption

RUSTSEC-2023-0001

On Windows, configuring a named pipe server with pipe_mode will force ServerOptions::reject_remote_clients as false.

This drops any intended explicit configuration for the reject_remote_clients that may have been set as true previously.

The default setting of reject_remote_clients is normally true meaning the default is also overridden as false.

Workarounds

Ensure that pipe_mode is set first after initializing a ServerOptions. For example:

let mut opts = ServerOptions::new();
opts.pipe_mode(PipeMode::Message);
opts.reject_remote_clients(true);