-
Notifications
You must be signed in to change notification settings - Fork 600
Closed
Description
Now cargo audit has found vulnerability in protobuf.
Please update your protobuf dependency on actual v3.
$ cargo audit
Fetching advisory database from `https://github.com/RustSec/advisory-db.git`
Loaded 741 security advisories (from /home/.cargo/advisory-db)
Updating crates.io index
Scanning Cargo.lock for vulnerabilities (528 crate dependencies)
Crate: protobuf
Version: 2.28.0
Title: Crash due to uncontrolled recursion in protobuf crate
Date: 2024-12-12
ID: RUSTSEC-2024-0437
URL: https://rustsec.org/advisories/RUSTSEC-2024-0437
Solution: No fixed upgrade is available!
Dependency tree:
protobuf 2.28.0
├── prometheus 0.13.4
│ ├── opentelemetry-prometheus 0.28.0
│ │ └── app 0.1.0
│ └── app 0.1.0
└── opentelemetry-prometheus 0.28.0
error: 1 vulnerability found!
azoyan and attila-lin
Metadata
Metadata
Assignees
Labels
No labels