Hi, Cargo does not perform SSH host key verification when cloning indexes and dependencies via SSH. An attacker could exploit this to perform man-in-the-middle (MITM) attacks. All Rust versions containing Cargo before 1.66.1 are vulnerable: https://www.openwall.com/lists/oss-security/2023/01/10/3 Best regards, Nico.
Whiteboard: (none) => MGA8TOO
CVE: (none) => CVE-2022-46176Status comment: (none) => Fixed in version 1.66.1Source RPM: (none) => rust-1.66.0-1.mga9.src.rpm
Assignee: bugsquad => rverschelde
Already had a security bug for rust. *** This bug has been marked as a duplicate of bug 30907 ***
Resolution: (none) => DUPLICATEStatus: NEW => RESOLVED