Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
内嵌的恶意代码
Vulnerability Title
droundy append-only-vec 处理逻辑错误漏洞
Vulnerability Description
droundy append-only-vec是droundy组织的一个提供并发追加操作且已分配元素地址保持稳定的Rust向量数据结构库。 droundy append-only-vec 0.1.9版本存在处理逻辑错误漏洞,该漏洞源于包含恶意依赖,该依赖注册到命令与控制服务器以提供任意代码执行,可能导致编译使用该crate的项目时触发恶意代码执行。
CVSS Information
N/A
Vulnerability Type
N/A