The aliyun-oss-client unintentionally divulges the authentication secret.
aliyun-oss-client
This bug was fixed in this commit by limiting the concerned traits to be pub only within the crate.
pub
{ "license": "CC0-1.0" }
{ "affected_functions": null, "affects": { "os": [], "functions": [], "arch": [] } }
{ "cvss": "CVSS:3.1/AV:P/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N", "informational": null, "categories": [ "crypto-failure" ] }