{"id":"GHSA-xphf-cx8h-7q9g","aliases":["RUSTSEC-2023-0072"],"url":"https://o3.security/vulnerability/GHSA-xphf-cx8h-7q9g","summary":"`openssl` `X509StoreRef::objects` is unsound","details":"This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back.\n\nUse of this function should be replaced with `X509StoreRef::all_certificates`.\n","published":"2023-11-28T20:51:08Z","modified":"2026-02-04T02:18:36.047186Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"openssl","fixedVersion":"0.10.60"}],"fix":{"url":"https://github.com/sfackler/rust-openssl/commit/cf9681a55cabd4cb9f1475bde17b5079f2a0384e","label":"sfackler/rust-openssl@cf9681a"},"references":[{"type":"WEB","url":"https://github.com/sfackler/rust-openssl/issues/2096"},{"type":"WEB","url":"https://github.com/sfackler/rust-openssl/commit/cf9681a55cabd4cb9f1475bde17b5079f2a0384e"},{"type":"PACKAGE","url":"https://github.com/sfackler/rust-openssl"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2023-0072.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-04T02:18:36.047186Z"}}