Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXE5aDItNHhoZi0yM3h4
Data races in im
An issue was discovered in the im crate prior to 15.1.0 for Rust. Because TreeFocus does not have bounds on its Send trait or Sync trait, a data race can occur.
Permalink: https://github.com/advisories/GHSA-q9h2-4xhf-23xxJSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXE5aDItNHhoZi0yM3h4
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 3 years ago
Updated: over 1 year ago
CVSS Score: 4.7
CVSS vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Identifiers: GHSA-q9h2-4xhf-23xx, CVE-2020-36204
References:
- https://nvd.nist.gov/vuln/detail/CVE-2020-36204
- https://github.com/bodil/im-rs/issues/157
- https://rustsec.org/advisories/RUSTSEC-2020-0096.html
- https://github.com/bodil/im-rs/pull/158
- https://github.com/bodil/im-rs/releases/tag/v15.1.0
- https://github.com/bodil/im-rs/commit/0b3a7b228b0fe70446393f55c8b893f349f3f6bd
- https://github.com/advisories/GHSA-q9h2-4xhf-23xx
Blast Radius: 15.6
Affected Packages
cargo:im
Dependent packages: 136Dependent repositories: 2,081
Downloads: 12,995,996 total
Affected Version Ranges: >= 12.0.0, < 15.1.0
Fixed in: 15.1.0
All affected versions: 12.0.0, 12.1.0, 12.2.0, 12.3.0, 12.3.1, 12.3.2, 12.3.3, 12.3.4, 13.0.0, 14.0.0, 14.1.0, 14.2.0, 14.3.0, 15.0.0
All unaffected versions: 1.0.0, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 3.0.0, 4.0.0, 4.0.1, 4.1.0, 5.0.0, 6.0.0, 7.0.0, 7.1.0, 8.0.0, 9.0.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.0.1, 11.0.2, 15.1.0