{"id":"GHSA-f2wx-xjfw-xjv6","aliases":[],"url":"https://o3.security/vulnerability/GHSA-f2wx-xjfw-xjv6","summary":"topgrade Time-of-check Time-of-use (TOCTOU) Race Condition in remove_dir_all","details":"### Summary\nhttps://github.com/advisories/GHSA-mc8h-8q98-g5hr\nhttps://github.com/XAMPPRocky/remove_dir_all/commit/7247a8b6ee59fc99bbb69ca6b3ca4bfd8c809ead\n\n`tempfile` v0.4.26 ships with affected `remove_dir_all` v0.5.3 and so blocks my deployment of v12 to openSUSE distribution because it imposes a clean `cargo audit`\n\nUpdating `tempfile` is warranted","published":"2023-07-17T18:21:58Z","modified":"2023-07-17T18:21:58Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"topgrade","fixedVersion":"12.0.1"}],"fix":{"url":"https://github.com/XAMPPRocky/remove_dir_all/commit/7247a8b6ee59fc99bbb69ca6b3ca4bfd8c809ead","label":"XAMPPRocky/remove_dir_all@7247a8b"},"references":[{"type":"WEB","url":"https://github.com/topgrade-rs/topgrade/security/advisories/GHSA-f2wx-xjfw-xjv6"},{"type":"WEB","url":"https://github.com/XAMPPRocky/remove_dir_all/commit/7247a8b6ee59fc99bbb69ca6b3ca4bfd8c809ead"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mc8h-8q98-g5hr"},{"type":"PACKAGE","url":"https://github.com/topgrade-rs/topgrade"},{"type":"WEB","url":"https://github.com/topgrade-rs/topgrade/releases/tag/v12.0.0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-07-17T18:21:58Z"}}