🦀 Security issue #Rust

👉 Cargo didn't perform SSH host key verification when cloning indexes and dependencies via SSH

👉 An attacker could exploit this to perform man-in-the-middle attacks

👉 Cargo before 1.66.1 vulnerable

https://blog.rust-lang.org/2023/01/10/cve-2022-46176.html

#rustlang #rustaceans #rusties #rustacean #infosec

Security advisory for Cargo (CVE-2022-46176) | Rust Blog

Empowering everyone to build reliable and efficient software.