GHSA-wv4p-jp67-jr97

Suggest an improvement
Source
https://github.com/advisories/GHSA-wv4p-jp67-jr97
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-wv4p-jp67-jr97/GHSA-wv4p-jp67-jr97.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wv4p-jp67-jr97
Aliases
Published
2021-08-25T20:50:05Z
Modified
2023-11-08T04:03:39.710071Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Data races in magnetic
Details

Affected versions of this crate unconditionally implemented Sync and Send traits for MPMCConsumer and MPMCProducer types. This allows users to send types that do not implement Send trait across thread boundaries, which can cause a data race. The flaw was corrected in the 2.0.1 release by adding T: Send bound to affected Sync/Send trait implementations.

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [
        "CWE-362"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2021-08-19T18:56:44Z"
}
References

Affected packages

crates.io / magnetic

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.1