The aliyun-oss-client unintentionally divulges the authentication secret.
aliyun-oss-client
This bug was fixed in this commit by limiting the concerned traits to be pub only within the crate.
pub
{ "license": "CC0-1.0" }
{ "affects": { "functions": [], "arch": [], "os": [] }, "affected_functions": null }
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2022-0089.json"
null
"CVSS:3.1/AV:P/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N"
[ "crypto-failure" ]