OSV 1.4.0 · github-reviewed · 修改于 2023-06-14 05:03
发布时间
2021-08-26 05:00
GitHub 审查时间
2021-08-07 01:45
NVD 发布时间
—
源文件
advisories/github-reviewed/2021/08/GHSA-39vw-qp34-rmwf/GHSA-39vw-qp34-rmwf.json
Affected versions of this crate did not properly check for recursion while deserializing aliases. This allows an attacker to make a YAML file with an alias referring to itself causing an abort. The flaw was corrected by checking the recursion depth.