CVE-2019-25010: Rust Failure Crate Vulnerable to Type confusion
(updated )
Safe Rust code can implement malfunctioning __private_get_type_id__
and cause type confusion when downcasting, which is an undefined behavior.
Users who derive Fail trait are not affected.
References
Detect and mitigate CVE-2019-25010 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →