chore(deps): update rust crate serde_with to 3.21.0 [security] - #21
Open
renovate[bot] wants to merge 1 commit into
Open
chore(deps): update rust crate serde_with to 3.21.0 [security]#21renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.0.0→3.21.0serde_with: KeyValueMap serialization panics on empty sequence or map entries
GHSA-7gcf-g7xr-8hxj
More information
Details
Summary
The public
KeyValueMapserializer assumes that each mapped element has at least one field or item to use as the map key, but it subtracts1from the caller-visible length before validating that assumption. An application that serializes attacker-controlled data through#[serde_as(as = "KeyValueMap<_>")]can be crashed by an empty inner sequence or map entry.Details
The affected public surface includes:
#[serde_as(as = "KeyValueMap<_>")]values throughserde_json::to_stringor any other Serde serializer`KeyValueMapconversions for sequence and map-backed entries`The root cause is: The
KeyValueMapserializer preallocatingVec::with_capacity(len - 1)orVec::with_capacity(len.unwrap_or(17) - 1)before checking that the element actually contains the required first key field or item.The vulnerable data/control flow is: attacker-controlled empty entry ->
serde_json::to_string->KeyValueMap<TAs>::serialize_as->SeqAsMapSerializer::{serialize_seq,serialize_map}->Vec::with_capacity(len - 1)orVec::with_capacity(len.unwrap_or(17) - 1)-> panicRelevant source locations:
serde_with/src/key_value_map.rs:590serde_with/src/key_value_map.rs:599serde_with/src/key_value_map.rs:613serde_with/src/key_value_map.rs:632serde_with/src/key_value_map.rs:648PoC
Impact
A local attacker who can trigger serialization of attacker-controlled data through
KeyValueMapcan terminate the process, causing a denial of service.Severity
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Release Notes
jonasbb/serde_with (serde_with)
v3.21.0: serde_with v3.21.0Compare Source
Security
GHSA-7gcf-g7xr-8hxj: KeyValueMap serialization panics on empty sequence or map entries
Bad or attacker controlled values could cause a panic while allocating too large values.
Fixed in #966 by setting a maximum allocation size during the creation of collections like
Vecor sets.Thanks to @7thParkk for reporting the issue.
Added
NoneAsZeroadapter that mapsOption<NonZero*>to a plain integer, encodingNoneas0by @SAY-5 (#486)Changed
Fixed
unused_qualificationsand fix the resulting findings by @lms0806 (#962)v3.20.0: serde_with v3.20.0Compare Source
Added
base58encoding, similar to the existingbase64setup by @mitinarseny (#943)Fixed
base64withschemarssupport by @mitinarseny (#9949)v3.19.0: serde_with v3.19.0Compare Source
Added
Add support for
hashbrownv0.17 (#940)This extends the existing support for
hashbrownto the newly released version.v3.18.0: serde_with v3.18.0Compare Source
Added
OneOrManywith more sequence and set types (#929)Changed
darlingdependencyv3.17.0: serde_with v3.17.0Compare Source
Added
OneOrManywithsmallvecv1 (#920, #922)Changed
yaml_serdefor a maintained yaml dependency by @kazan417 (#921)yaml_serdedev-dependency.v3.16.1: serde_with v3.16.1Compare Source
Fixed
JsonSchemaAsofSetPreventDuplicatesandSetLastValueWins. (#906, #907)v3.16.0: serde_with v3.16.0Compare Source
Added
smallvecv1 under thesmallvec_1feature flag by @isharma228 (#895)JsonSchemaAsimplementation forjson::JsonStringby @yogevm15 (#901)v3.15.1: serde_with v3.15.1Compare Source
Fixed
serde_core.v3.15.0: serde_with v3.15.0Compare Source
Added
Added error inspection to
VecSkipErrorandMapSkipErrorby @michelhe (#878)This allows interacting with the previously hidden error, for example for logging.
Checkout the newly added example to both types.
Allow documenting the types generated by
serde_conv!.The
serde_conv!macro now acceps outer attributes before the optional visibility modifier.This allow adding doc comments in the shape of
#[doc = "..."]or any other attributes, such as lint modifiers.Add support for
hashbrownv0.16 (#877)This extends the existing support for
hashbrownv0.14 and v0.15 to the newly released version.Changed
tomldev-dependency.v3.14.1: serde_with v3.14.1Compare Source
Fixed
Since macros are used to generate trait implementations, this is useful to understand the exact generated code.
v3.14.0: serde_with v3.14.0Compare Source
Added
Range,RangeFrom,RangeTo,RangeInclusive(#851)RangeToInclusiveis currently unsupported by serde.schemarsimplementations forBound,Range,RangeFrom,RangeTo,RangeInclusive.schemarsv1 under theschemars_1feature flagv3.13.0: serde_with v3.13.0Compare Source
Added
schemarsv0.9.0 under theschemars_0_9feature flag by @swlynch99 (#849)SerializeDisplayAltderive macro (#833)An alternative to the
SerializeDisplaymacro except instead of using theplain formatting like
format!("{}", ...), it serializes with theFormatter::alternateflag set to true, likeformat!("{:#}", ...)Changed
serde_with::rust::unwrap_or_skipto support deserializing references by @beroal (#832)jsonschemadev-dependency.serde_convavailable without thestdfeature by @arilou (#839)schemarsv0.9.0 by @swlynch99 (#849)Fixed
DurationSecondstypes and other variants more accessible even withoutstd(#845)v3.12.0: serde_with v3.12.0Compare Source
Added
with_suffix!macro, which puts a suffix on every struct field by @fgardt (#381/#797)Changed
Cargo.tomlfiles by @nyurik (#803)Fixed
v3.11.0: serde_with v3.11.0Compare Source
Added
Add support for
hashbrownv0.15 (#787/#790)This extends the existing support for
hashbrownv0.14 to the newly released version.v3.10.0: serde_with v3.10.0Compare Source
Added
Add newline separator by @jayvdb (#777)
The
UnixLineSeparatorandDosLineSeparatorcan be used together withStringWithSeparator.Fixed
Proper handling of
cfg_attrin theserde_asmacro by @sivizius (#782)This allows to parse more valid forms of the
cfg_attrmacro, including multiple values and attribute that do not follow thekey = valueschema.v3.9.0: serde_with v3.9.0Compare Source
Added
Deserialize a map` and skip all elements failing to deserialize by @johnmave126 (#763)
MapSkipErroracts like a map (HashMap/BTreeMap), but keys or values that fail to deserialize, like are ignored.For formats with heterogeneously typed maps, we can collect only the elements where both key and value are deserializable.
This is also useful in conjunction to
#[serde(flatten)]to ignore some entries when capturing additional fields.v3.8.3: serde_with v3.8.3Compare Source
Fixed
schemars_0_8is used with thepreserve_orderfeatures (#762)v3.8.2: serde_with v3.8.2Compare Source
Changed
timedependency.The
timeversion needed to be updated for nightly compatibility.Fixed
JsonSchemaAsforOneOrManyinstead ofJsonSchemaby @swlynch99 (#760)v3.8.1: serde_with v3.8.1Compare Source
Fixed
schemars(deserialize_with = "...")annotations, asschemarsdoes not support them (#735)Thanks to @sivizius for reporting the issue.
v3.8.0: serde_with v3.8.0Compare Source
Added
JsonSchemaAsforPickFirstby @swlynch99 (#721)Changed
base64dependency to v0.22 (#724)Fixed
serde_convregressed and triggeredclippy::ptr_argand add test to prevent future problems. (#731)v3.7.0: serde_with v3.7.0Compare Source
Added
JsonSchemaAsforEnumMapby @swlynch99 (#697)JsonSchemaAsforIfIsHumanReadableby @swlynch99 (#717)JsonSchemaAsforKeyValueMapby @swlynch99 (#713)JsonSchemaAsforOneOrManyby @swlynch99 (#719)Fixed
schema_withattributes on fields withschemarsannotations by @swlynch99 (#715)This extends the existing avoidance mechanism to a new variant fixing #712.
v3.6.1: serde_with v3.6.1Compare Source
Changed
This allows parallel compilation of
serdeandserde_derivewhich can speed up the wallclock time.It requires that downstream crates do not use the "derive" feature either.
v3.6.0: serde_with v3.6.0Compare Source
Added
IfIsHumanReadablefor conditional implementation by @irriden (#690)Used to specify different transformations for text-based and binary formats.
JsonSchemaAsimpls for allDuration*andTimestamp*adaptors by @swlynch99 (#685)Changed
regexdependency.v3.5.1: serde_with v3.5.1Compare Source
Fixed
serde_asmacro now better detects existingschemarsattributes on fields and incorporates them by @swlynch99 (#682)This avoids errors on existing
#[schemars(with = ...)]annotations.v3.5.0: serde_with v3.5.0Compare Source
Added
schemarsintegration added by @swlynch99 (#666)The support uses a new
Schematop-level item which implementsJsonSchemaThe
serde_asmacro can now detectschemarsusage and emits matching annotations for all fields withserde_asattribute.Many types of this crate come already with support for the
schemars, but support is not complete and will be extended over time.v3.4.0: serde_with v3.4.0Compare Source
Lower minimum required serde version to 1.0.152 (#653)
Thanks to @banool for submitting the PR.
This allows people that have a problem with 1.0.153 to still use
serde_with.Add support for
core::ops::Bound(#655)Thanks to @qsantos for submitting the PR.
v3.3.0: serde_with v3.3.0Compare Source
Added
Support the
hashbrowntypeHashMapandHashSet(#636, #637)Thanks to @OliverNChalk for raising the issue and submitting a PR.
This extends the existing support for
HashMaps andHashSets to thehashbrowncrate v0.14.The same conversions as for the
stdandindexmaptypes are available, like general support for#[serde_as]and converting it to/from sequences or maps.Changed
Generalize some trait bounds for
DeserializeAsimplementationsWhile working on #637 it came to light that some of the macros for generating
DeserializeAsimplementations were not as generic as they could.This means they didn't work with custom hasher types, but only the default hashers.
This has now been fixed and custom hashers should work better, as long as they implement
BuildHasher + Default.(internal) Change how features are documented (#639)
This change moves the feature documentation into
Cargo.tomlin a format that can be read by lib.rs.It will improve the generated features documentation there.
The page with all features remains in the guide but is now generated from the
Cargo.tomlinformation.v3.2.0: serde_with v3.2.0Compare Source
Added
Support for v1 is already available using the
indexmap_1feature.This adds identical support for v2 of indexmap using the
indexmap_2feature.Changed
Fixed
i64::MINusingTimestampSeconds<i64>(#632, #633)Thanks to @hollmmax for reporting and fixing the issue.
v3.1.0: serde_with v3.1.0Compare Source
Added
Add
FromIntoRefandTryFromIntoRef(#618)Thanks to @oblique for submitting the PR.
The new types are similar to the existing
FromIntoandTryFromIntotypes.They behave different during serialization, allowing the removal of the
Clonebound on theirSerializeAstrait implementationChanged
serde_as(#607)cfg_eval.Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.