Junglewise Threat Intelligence

RUSTSEC-2023-0023 - `openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file read

Severity: info ยท Published 2023-03-24

Technologies: openssl (crates.io). Vendors: crates.io.

Executive brief

`openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file read

Affected products

  • crates.io openssl

Related threats