An open API service providing security vulnerability metadata for many open source software ecosystems.

GSA_kwCzR0hTQS1qcTY2LXhoNDctajlmM84AArqn

Critical EPSS: 0.00619% (0.69058 Percentile) EPSS:

Type confusion if __private_get_type_id__ is overriden

Affected Packages Affected Versions Fixed Versions
cargo:failure
PURL: pkg:cargo/failure
<= 0.1.8 No known fixed version
3,128 Dependent packages
14,385 Dependent repositories
38,320,319 Downloads total

Affected Version Ranges

All affected versions

0.0.1, 0.1.0, 0.1.1, 0.1.2, 0.1.3, 0.1.4, 0.1.5, 0.1.6, 0.1.7, 0.1.8

An issue was discovered in the failure crate through 0.1.5 for Rust. It may introduce "compatibility hazards" in some applications, and has a type confusion flaw when downcasting. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: This may overlap CVE-2019-25010.

References: