Cross-site scripting in Rust Programming Language - CVE-2023-40030

 

Cross-site scripting in Rust Programming Language - CVE-2023-40030

Published: September 2, 2024


Vulnerability identifier: #VU96700
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2023-40030
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data when downloading Rust project dependencies with Cargo. A remote attacker can execute arbitrary HTML and script code in user's browser in context of vulnerable website.


Affected software

Rust Programming Language
Oracle Solaris
Amazon Linux AMI
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Development Tools Module
openSUSE Leap
Fedora
rust-cargo-credential
rust-cargo-credential-libsecret
rust-cargo-c
rust-git2-curl
rust-cbindgen0.24
rust-cbindgen
rust-crates-io
rust-cargo
rust
rust1.72-test
rust1.72
rust1.72-debuginfo
cargo1.72-debuginfo
cargo1.72
cargo

How to mitigate CVE-2023-40030

Install updates from vendor's website.

Rust Programming Language - update to 1.72.0
Oracle Solaris - update to 11.4 SRU 71
rust-cargo-credential - update to 0.3.0-1.fc40
rust-cargo-credential-libsecret - update to 0.3.1-1.fc40
rust-cargo-c - update to 0.9.27-1.fc40
rust-git2-curl - update to 0.18.0-1.fc40
rust-cbindgen0.24 - update to 0.24.5-1.fc40
rust-cbindgen - update to 0.26.0-1.fc40
rust-crates-io - update to 0.38.0-1.fc40
rust-cargo - update to 0.74.0-1.fc40
rust - update to 1.68.2-1
rust1.72-test - update to 1.72.0-150400.9.3.1
rust1.72 - update to 1.72.0-150400.9.3.1
rust1.72-debuginfo - update to 1.72.0-150400.9.3.1
cargo1.72-debuginfo - update to 1.72.0-150400.9.3.1
cargo1.72 - update to 1.72.0-150400.9.3.1
cargo - update to 1.72.0-150400.24.24.1
rust - update to 1.72.0-150400.24.24.1

External References

Related Security Bulletins