-
Notifications
You must be signed in to change notification settings - Fork 16
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix(deps): update rust crate object_store to 0.10.2 [security] - autoclosed #131
Closed
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
renovate
bot
force-pushed
the
renovate/crate-object_store-vulnerability
branch
from
July 28, 2024 14:33
f289796
to
22919f1
Compare
renovate
bot
changed the title
fix(deps): update rust crate object_store to 0.10.2 [security]
fix(deps): update rust crate object_store to 0.10 [security]
Jul 28, 2024
renovate
bot
force-pushed
the
renovate/crate-object_store-vulnerability
branch
from
July 28, 2024 16:21
22919f1
to
f190d9c
Compare
renovate
bot
changed the title
fix(deps): update rust crate object_store to 0.10 [security]
fix(deps): update rust crate object_store to 0.10.2 [security]
Jul 28, 2024
renovate
bot
force-pushed
the
renovate/crate-object_store-vulnerability
branch
from
October 9, 2024 09:08
f190d9c
to
f09186f
Compare
renovate
bot
changed the title
fix(deps): update rust crate object_store to 0.10.2 [security]
fix(deps): update rust crate object_store to 0.11 [security]
Oct 9, 2024
renovate
bot
force-pushed
the
renovate/crate-object_store-vulnerability
branch
from
October 9, 2024 12:22
f09186f
to
017586d
Compare
renovate
bot
changed the title
fix(deps): update rust crate object_store to 0.11 [security]
fix(deps): update rust crate object_store to 0.10.2 [security]
Oct 9, 2024
renovate
bot
force-pushed
the
renovate/crate-object_store-vulnerability
branch
from
October 28, 2024 15:38
017586d
to
dc34e9d
Compare
renovate
bot
changed the title
fix(deps): update rust crate object_store to 0.10.2 [security]
fix(deps): update rust crate object_store to 0.11 [security]
Oct 28, 2024
renovate
bot
force-pushed
the
renovate/crate-object_store-vulnerability
branch
from
October 28, 2024 19:40
dc34e9d
to
e65fa6c
Compare
renovate
bot
changed the title
fix(deps): update rust crate object_store to 0.11 [security]
fix(deps): update rust crate object_store to 0.10.2 [security]
Oct 28, 2024
renovate
bot
force-pushed
the
renovate/crate-object_store-vulnerability
branch
from
October 30, 2024 07:34
e65fa6c
to
85a026e
Compare
renovate
bot
changed the title
fix(deps): update rust crate object_store to 0.10.2 [security]
fix(deps): update rust crate object_store to 0.11 [security]
Oct 30, 2024
renovate
bot
force-pushed
the
renovate/crate-object_store-vulnerability
branch
from
October 30, 2024 11:33
85a026e
to
55bdfee
Compare
renovate
bot
changed the title
fix(deps): update rust crate object_store to 0.11 [security]
fix(deps): update rust crate object_store to 0.10.2 [security]
Oct 30, 2024
renovate
bot
force-pushed
the
renovate/crate-object_store-vulnerability
branch
from
November 1, 2024 19:08
55bdfee
to
18eead4
Compare
renovate
bot
changed the title
fix(deps): update rust crate object_store to 0.10.2 [security]
fix(deps): update rust crate object_store to 0.11 [security]
Nov 1, 2024
renovate
bot
force-pushed
the
renovate/crate-object_store-vulnerability
branch
from
November 1, 2024 21:53
18eead4
to
cf10d31
Compare
renovate
bot
changed the title
fix(deps): update rust crate object_store to 0.11 [security]
fix(deps): update rust crate object_store to 0.10.2 [security]
Nov 1, 2024
renovate
bot
force-pushed
the
renovate/crate-object_store-vulnerability
branch
from
November 17, 2024 16:57
cf10d31
to
a50aa1d
Compare
renovate
bot
changed the title
fix(deps): update rust crate object_store to 0.10.2 [security]
fix(deps): update rust crate object_store to 0.11 [security]
Nov 17, 2024
renovate
bot
force-pushed
the
renovate/crate-object_store-vulnerability
branch
from
November 17, 2024 19:17
a50aa1d
to
e99b074
Compare
renovate
bot
changed the title
fix(deps): update rust crate object_store to 0.11 [security]
fix(deps): update rust crate object_store to 0.10.2 [security]
Nov 17, 2024
renovate
bot
force-pushed
the
renovate/crate-object_store-vulnerability
branch
from
December 2, 2024 11:50
e99b074
to
f6ae71f
Compare
renovate
bot
changed the title
fix(deps): update rust crate object_store to 0.10.2 [security]
fix(deps): update rust crate object_store to 0.11 [security]
Dec 2, 2024
renovate
bot
force-pushed
the
renovate/crate-object_store-vulnerability
branch
from
December 2, 2024 15:13
f6ae71f
to
e1363c2
Compare
renovate
bot
changed the title
fix(deps): update rust crate object_store to 0.11 [security]
fix(deps): update rust crate object_store to 0.10.2 [security]
Dec 2, 2024
renovate
bot
force-pushed
the
renovate/crate-object_store-vulnerability
branch
from
December 17, 2024 19:43
e1363c2
to
1e466e8
Compare
renovate
bot
changed the title
fix(deps): update rust crate object_store to 0.10.2 [security]
fix(deps): update rust crate object_store to 0.11 [security]
Dec 17, 2024
renovate
bot
force-pushed
the
renovate/crate-object_store-vulnerability
branch
from
December 17, 2024 22:18
1e466e8
to
87a3d03
Compare
renovate
bot
changed the title
fix(deps): update rust crate object_store to 0.11 [security]
fix(deps): update rust crate object_store to 0.10.2 [security]
Dec 17, 2024
renovate
bot
force-pushed
the
renovate/crate-object_store-vulnerability
branch
from
December 22, 2024 19:49
87a3d03
to
73b7433
Compare
renovate
bot
changed the title
fix(deps): update rust crate object_store to 0.10.2 [security]
fix(deps): update rust crate object_store to 0.11 [security]
Dec 22, 2024
renovate
bot
force-pushed
the
renovate/crate-object_store-vulnerability
branch
from
December 22, 2024 23:03
73b7433
to
5170b45
Compare
renovate
bot
changed the title
fix(deps): update rust crate object_store to 0.11 [security]
fix(deps): update rust crate object_store to 0.10.2 [security]
Dec 22, 2024
renovate
bot
changed the title
fix(deps): update rust crate object_store to 0.10.2 [security]
fix(deps): update rust crate object_store to 0.10.2 [security] - autoclosed
Jan 6, 2025
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
None yet
0 participants
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.9
->0.10.2
GitHub Vulnerability Alerts
CVE-2024-41178
Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (
object_store
crate), version 0.10.1 and earlier on all platforms using AWS WebIdentityTokens.On certain error conditions, the logs may contain the OIDC token passed to AssumeRoleWithWebIdentity https://docs.aws.amazon.com/STS/latest/APIReference/API_AssumeRoleWithWebIdentity.html . This allows someone with access to the logs to impersonate that identity, including performing their own calls to AssumeRoleWithWebIdentity, until the OIDC token expires. Typically OIDC tokens are valid for up to an hour, although this will vary depending on the issuer.
Users are recommended to use a different AWS authentication mechanism, disable logging or upgrade to version 0.10.2, which fixes this issue.
Details:
When using AWS WebIdentityTokens with the object_store crate, in the event of a failure and automatic retry, the underlying reqwest error, including the full URL with the credentials, potentially in the parameters, is written to the logs.
Thanks to Paul Hatcherian for reporting this vulnerability
Release Notes
apache/arrow-rs (object_store)
v0.10.2
Compare Source
v0.10.1
Compare Source
v0.10.0
Compare Source
v0.9.1
Compare Source
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.