GHSA-q9h2-4xhf-23xx

Suggest an improvement
Source
https://github.com/advisories/GHSA-q9h2-4xhf-23xx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-q9h2-4xhf-23xx/GHSA-q9h2-4xhf-23xx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-q9h2-4xhf-23xx
Aliases
Published
2021-08-25T20:51:36Z
Modified
2023-11-08T04:03:41.356226Z
Severity
  • 4.7 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Data races in im
Details

An issue was discovered in the im crate prior to 15.1.0 for Rust. Because TreeFocus does not have bounds on its Send trait or Sync trait, a data race can occur.

Database specific
{
    "nvd_published_at": "2021-01-26T18:15:00Z",
    "github_reviewed_at": "2021-08-19T18:49:57Z",
    "severity": "MODERATE",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-662"
    ]
}
References

Affected packages

crates.io / im

Package

Affected ranges

Type
SEMVER
Events
Introduced
12.0.0
Fixed
15.1.0