RUSTSEC-2021-0004

Source
https://rustsec.org/advisories/RUSTSEC-2021-0004
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2021-0004.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2021-0004
Aliases
Published
2021-01-17T12:00:00Z
Modified
2023-11-08T04:05:16Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Missing Send bound for Lazy
Details

All current versions of this crate allow causing data races in safe code.

The flaw will be fixed in the next release.

Database specific
{
    "license": "CC0-1.0"
}
References

Affected packages

crates.io / lazy-init

Package

Name
lazy-init
View open source insights on deps.dev
Purl
pkg:cargo/lazy-init

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-0
Fixed
0.4.1-0

Ecosystem specific

{
    "affected_functions": null,
    "affects": {
        "arch": [],
        "functions": [],
        "os": []
    }
}

Database specific

categories
[
    "memory-corruption"
]
cvss
"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
informational
null
source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2021-0004.json"