This project might be open to known security vulnerabilities , which can be prevented by tightening the version range of affected dependencies. Find detailed information at the bottom .
Crate rusoto_mock
Dependencies (6 total, 1 outdated, 1 possibly insecure)
Crate credential_service_mock
Dependencies (2 total, 1 outdated, 2 possibly insecure)
Crate Required Latest Status hyper ⚠️ ^0.14
1.3.1
out of date tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_core
Dependencies (16 total, 5 outdated, 2 possibly insecure)
Dev dependencies (5 total, 2 outdated, 1 possibly insecure)
Build dependencies (1 total, all up-to-date)
Crate rusoto_credential
Dependencies (10 total, 1 outdated, 4 possibly insecure)
Dev dependencies (5 total, 2 outdated, 1 possibly insecure)
Crate rusoto_signature
Dependencies (16 total, 7 outdated, 3 possibly insecure)
Dev dependencies (3 total, 1 possibly insecure)
Build dependencies (1 total, all up-to-date)
Crate rusoto_accessanalyzer
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_acm
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_acm_pca
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_alexaforbusiness
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_amplify
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_apigateway
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_apigatewaymanagementapi
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_apigatewayv2
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_appconfig
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_application_autoscaling
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_application_insights
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_appmesh
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_appstream
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_appsync
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_athena
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_autoscaling
Dependencies (7 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_autoscaling_plans
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_backup
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_batch
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_budgets
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_ce
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_chime
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_cloud9
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_clouddirectory
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_cloudformation
Dependencies (7 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_cloudfront
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_cloudhsm
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_cloudhsmv2
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_cloudsearch
Dependencies (7 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_cloudsearchdomain
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_cloudtrail
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_cloudwatch
Dependencies (7 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_codebuild
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_codecommit
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_codedeploy
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_codeguru_reviewer
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_codeguruprofiler
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_codepipeline
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_codestar
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_codestar_connections
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_codestar_notifications
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_cognito_identity
Dependencies (6 total, 1 possibly insecure)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_cognito_idp
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_cognito_sync
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_comprehend
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_comprehendmedical
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_compute_optimizer
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_config
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_connect
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_connectparticipant
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_cur
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_dataexchange
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_datapipeline
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_datasync
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_dax
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_detective
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_devicefarm
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_directconnect
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_discovery
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_dlm
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_dms
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_docdb
Dependencies (7 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_ds
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_dynamodb
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_dynamodbstreams
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_ebs
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_ec2
Dependencies (7 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_ec2_instance_connect
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_ecr
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_ecs
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_efs
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_eks
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_elastic_inference
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_elasticache
Dependencies (7 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_elasticbeanstalk
Dependencies (7 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_elastictranscoder
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_elb
Dependencies (7 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_elbv2
Dependencies (7 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_emr
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_es
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_events
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_firehose
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_fms
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_forecast
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_forecastquery
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_frauddetector
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_fsx
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_gamelift
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_glacier
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_globalaccelerator
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_glue
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_greengrass
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_groundstation
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_guardduty
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_health
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_iam
Dependencies (7 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_imagebuilder
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_importexport
Dependencies (7 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_inspector
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_iot
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_iot_data
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_iot_jobs_data
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_iot1click_devices
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_iot1click_projects
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_iotanalytics
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_iotevents
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_iotevents_data
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_iotsecuretunneling
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_iotthingsgraph
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_kafka
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_kendra
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_kinesis
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_kinesis_video_archived_media
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_kinesis_video_media
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_kinesis_video_signaling
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_kinesisanalytics
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_kinesisanalyticsv2
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_kinesisvideo
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_kms
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_lakeformation
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_lambda
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_lex_models
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_lex_runtime
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_license_manager
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_lightsail
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_logs
Dependencies (5 total, all up-to-date)
Dev dependencies (2 total, 2 possibly insecure)
Crate Required Latest Status chrono ⚠️ ^0.4
0.4.38
maybe insecure tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_machinelearning
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_managedblockchain
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_marketplace_catalog
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_marketplace_entitlement
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_marketplacecommerceanalytics
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_mediaconnect
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_mediaconvert
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_medialive
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_mediapackage
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_mediapackage_vod
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_mediastore
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_mediatailor
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_meteringmarketplace
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_mgh
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_migrationhub_config
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_mq
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_mturk
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_neptune
Dependencies (7 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_networkmanager
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_opsworks
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_opsworkscm
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_organizations
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_outposts
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_personalize
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_personalize_events
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_personalize_runtime
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_pi
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_pinpoint_email
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_pinpoint_sms_voice
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_polly
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_pricing
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_qldb
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_qldb_session
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_quicksight
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_ram
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_rds
Dependencies (7 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_rds_data
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_redshift
Dependencies (7 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_rekognition
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_resource_groups
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_resourcegroupstaggingapi
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_robomaker
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_route53
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_route53domains
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_route53resolver
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_s3
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_sagemaker
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_sagemaker_a2i_runtime
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_sagemaker_runtime
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_savingsplans
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_schemas
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_sdb
Dependencies (7 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_secretsmanager
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_securityhub
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_serverlessrepo
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_service_quotas
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_servicecatalog
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_servicediscovery
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_ses
Dependencies (7 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_sesv2
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_shield
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_signer
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_sms
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_sms_voice
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_snowball
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_sns
Dependencies (7 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_sqs
Dependencies (7 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_ssm
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_sso
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_sso_oidc
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_stepfunctions
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_storagegateway
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_sts
Dependencies (8 total, 1 possibly insecure)
Dev dependencies (2 total, 1 possibly insecure)
Crate Required Latest Status tempfile ^3.1.0
3.10.1
up to date tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_support
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_swf
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_textract
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_transcribe
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_transfer
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_translate
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_waf
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_waf_regional
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_workdocs
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_workmail
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_workmailmessageflow
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_workspaces
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Crate rusoto_xray
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, 1 possibly insecure)
Crate Required Latest Status tokio ⚠️ ^1.0
1.37.0
maybe insecure
Security Vulnerabilities chrono
: Potential segfault in `localtime_r` invocationsRUSTSEC-2020-0159
Impact
Unix-like operating systems may segfault due to dereferencing a dangling pointer in specific circumstances. This requires an environment variable to be set in a different thread than the affected functions. This may occur without the user's knowledge, notably in a third-party library.
Workarounds
No workarounds are known.
References
hyper
: Lenient `hyper` header parsing of `Content-Length` could allow request smugglingRUSTSEC-2021-0078
hyper
's HTTP header parser accepted, according to RFC 7230, illegal contents inside Content-Length
headers.
Due to this, upstream HTTP proxies that ignore the header may still forward them along if it chooses to ignore the error.
To be vulnerable, hyper
must be used as an HTTP/1 server and using an HTTP proxy upstream that ignores the header's contents
but still forwards it. Due to all the factors that must line up, an attack exploiting this vulnerability is unlikely.
hyper
: Integer overflow in `hyper`'s parsing of the `Transfer-Encoding` header leads to data lossRUSTSEC-2021-0079
When decoding chunk sizes that are too large, hyper
's code would encounter an integer overflow. Depending on the situation,
this could lead to data loss from an incorrect total size, or in rarer cases, a request smuggling attack.
To be vulnerable, you must be using hyper
for any HTTP/1 purpose, including as a client or server, and consumers must send
requests or responses that specify a chunk size greater than 18 exabytes. For a possible request smuggling attack to be possible,
any upstream proxies must accept a chunk size greater than 64 bits.
tokio
: reject_remote_clients Configuration corruptionRUSTSEC-2023-0001
On Windows, configuring a named pipe server with pipe_mode will force ServerOptions ::reject_remote_clients as false
.
This drops any intended explicit configuration for the reject_remote_clients that may have been set as true
previously.
The default setting of reject_remote_clients is normally true
meaning the default is also overridden as false
.
Workarounds
Ensure that pipe_mode is set first after initializing a ServerOptions . For example:
let mut opts = ServerOptions::new();
opts.pipe_mode(PipeMode::Message);
opts.reject_remote_clients(true);
Patched
>=1.18.4, <1.19.0
>=1.20.3, <1.21.0
>=1.23.1
shlex
: Multiple issues involving quote APIRUSTSEC-2024-0006
Issue 1: Failure to quote characters
Affected versions of this crate allowed the bytes {
and \xa0
to appear
unquoted and unescaped in command arguments.
If the output of quote
or join
is passed to a shell, then what should be a
single command argument could be interpreted as multiple arguments.
This does not directly allow arbitrary command execution (you can't inject a
command substitution or similar). But depending on the command you're running,
being able to inject multiple arguments where only one is expected could lead
to undesired consequences, potentially including arbitrary command execution.
The flaw was corrected in version 1.2.1 by escaping additional characters.
Updating to 1.3.0 is recommended, but 1.2.1 offers a more minimal fix if
desired.
Workaround: Check for the bytes {
and \xa0
in quote
/join
input or
output.
(Note: {
is problematic because it is used for glob expansion. \xa0
is
problematic because it's treated as a word separator in specific
environments .)
Issue 2: Dangerous API w.r.t. nul bytes
Version 1.3.0 deprecates the quote
and join
APIs in favor of try_quote
and try_join
, which behave the same except that they have Result
return
type, returning Err
if the input contains nul bytes.
Strings containing nul bytes generally cannot be used in Unix command arguments
or environment variables, and most shells cannot handle nul bytes even
internally. If you try to pass one anyway, then the results might be
security-sensitive in uncommon scenarios. More details here.
Due to the low severity, the behavior of the original quote
and join
APIs
has not changed; they continue to allow nuls.
Workaround: Manually check for nul bytes in quote
/join
input or output.
Issue 3: Lack of documentation for interactive shell risks
The quote
family of functions does not and cannot escape control characters.
With non-interactive shells this is perfectly safe, as control characters have
no special effect. But if you writing directly to the standard input of an
interactive shell (or through a pty), then control characters can cause
misbehavior including arbitrary command injection.
This is essentially unfixable, and has not been patched. But as of version
1.3.0, documentation has been added.
Future versions of shlex
may add API variants that avoid the issue at the
cost of reduced portability.