Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cargo can be coerced to share credentials between registries
Vulnerability Description
Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Vulnerability Type
使用未经净化的URL路径进行授权决策
Vulnerability Title
Cargo 安全漏洞
Vulnerability Description
Cargo是The Rust Programming Language开源的一个 Rust 包管理器。 Cargo 1.68版本至1.96版本存在安全漏洞,该漏洞源于错误规范化使用稀疏索引协议的第三方注册表URL,如果托管提供商允许在同一域内托管多个具有任意名称的注册表,能够发布crates的攻击者可能获取同一注册表其他用户的凭据。
CVSS Information
N/A
Vulnerability Type
N/A