Skip to content

CVE-2020-26235 advisory for indirect time 0.1 dependency #306

@josecelano

Description

@josecelano

We use the chrono package, which uses the time package. The time package has a vulnerability.

Vulnerabilities: GHSA-wcg3-cvx6-7396
Latest version: https://crates.io/crates/chrono (0.4.24)
Time 0.1.45 is deprecated: https://crates.io/crates/time/0.1.45

They (chrono) plan to release a new version, but the vulnerability was reported on Nov 18, 2020.

More info:

Maybe we could try to disable some features to remove the dependency with the vulnerability.

Metadata

Metadata

Assignees

No one assigned

    Labels

    SecurityPublicly Connected to Security

    Type

    No type

    Projects

    Status

    No status

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions