CVE-2022-39397

MEDIUM

aliyun-oss-client < 0.8.1 - Exposure of Sensitive Information via Unintended Secret Disclosure

Title source: llm
STIX 2.1

Description

aliyun-oss-client is a rust client for Alibaba Cloud OSS. Users of this library will be affected, the incoming secret will be disclosed unintentionally. This issue has been patched in version 0.8.1.

Scores

CVSS v3 5.6
EPSS 0.0042
EPSS Percentile 33.8%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
aliyun-oss-client_project/aliyun-oss-client < 0.8.1
crates.io/aliyun-oss-client 0 - 0.8.1crates.io
Published Nov 22, 2022
Tracked Since Feb 18, 2026