Update hyper
in rocket_http v0.4.10
because of vulnerabilities
#1815
Labels
triage
A bug report being investigated
Description
Because of 2 vulnerabilities in
hyper
reported as:RUSTSEC-2021-0078
andRUSTSEC-2021-0079
an update of the dependencyhyper
is required from version0.10.x
to0.14.10
.This is not a patch version anymore (from
0.10
->0.14
) and thus might have other effects.References:
The is only effects v0.4.x of Rocket, not v0.5.x.
Although in there the minimum version might as well get updated from
0.14.9
to0.14.10
as the minimum version so to not include this vulnerability. Butcargo update
will update this automatically.Additional Context
This will be found by
cargo audit
since 2021/08/08:Dependency tree:
The text was updated successfully, but these errors were encountered: