{"id":"GHSA-3gxf-9r58-2ghg","aliases":["RUSTSEC-2023-0022"],"url":"https://o3.security/vulnerability/GHSA-3gxf-9r58-2ghg","summary":"`openssl` `X509NameBuilder::build` returned object is not thread safe","details":"OpenSSL has a `modified` bit that it can set on on `X509_NAME` objects. If this bit is set then the object is not thread-safe even when it appears the code is not modifying the value.\n\nThanks to David Benjamin (Google) for reporting this issue.\n","published":"2023-03-24T22:01:35Z","modified":"2023-11-08T04:14:38.793551Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"openssl","fixedVersion":"0.10.48"}],"fix":{"url":"https://github.com/sfackler/rust-openssl/pull/1854","label":"sfackler/rust-openssl#1854"},"references":[{"type":"WEB","url":"https://github.com/sfackler/rust-openssl/pull/1854"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2023-0022.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:14:38.793551Z"}}