Conversation
|
@ehuss do you agree that publishing an advisory for this is useful? Should it be |
cuviper
left a comment
There was a problem hiding this comment.
FYI we are discussing in the security response team whether this warrants a full CVE, but it didn't come to our attention until after the fact. I personally think at least informational = "unsound" is reasonable though, and I suppose we can update rustsec if we decide to go further.
Co-authored-by: Josh Stone <cuviper@gmail.com>
Thanks. @BoLu1225 can you add the |
Have confirmed with the maintainer and fixed the bug in latest release