Publish GHSA-wv8j-m3hx-924j

This commit is contained in:
advisory-database[bot]
2025-05-30 20:11:59 +00:00
parent 2e4bcd43f8
commit 556d262cdf
@@ -0,0 +1,55 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wv8j-m3hx-924j",
"modified": "2025-05-30T20:09:56Z",
"published": "2025-05-30T20:09:56Z",
"aliases": [],
"summary": "Arrow2 allows out of bounds access in public safe API",
"details": "`Rows::row_unchecked()` allows out of bounds access to the underlying buffer without sufficient checks.\n\nThe arrow2 crate is no longer maintained, so there are no plans to fix this issue. Users are advised to migrate to the arrow crate, instead.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
}
],
"affected": [
{
"package": {
"ecosystem": "crates.io",
"name": "arrow2"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "0.18.0"
}
]
}
]
}
],
"references": [
{
"type": "PACKAGE",
"url": "https://github.com/jorgecarleitao/arrow2"
},
{
"type": "WEB",
"url": "https://rustsec.org/advisories/RUSTSEC-2025-0038.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2025-05-30T20:09:56Z",
"nvd_published_at": null
}
}