Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pwqf-9h7j-7mv8

Опубликовано: 21 авг. 2020
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Incorrect threshold signature computation in TUF

Impact

Metadadata signature verification, as used in tuf.client.updater, counted each of multiple signatures with identical authorized keyids separately towards the threshold. Therefore, an attacker with access to a valid signing key could create multiple valid signatures in order to meet the minimum threshold of keys before the metadata was considered valid.

The tuf maintainers would like to thank Erik MacLean of Analog Devices, Inc. for reporting this issue.

Patches

A fix is available in version 0.12.2 or newer.

Workarounds

No workarounds are known for this issue.

References

Пакеты

Наименование

tuf

pip
Затронутые версииВерсия исправления

< 0.12.2

0.12.2

EPSS

Процентиль: 41%
0.00195
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 9.8
nvd
около 6 лет назад

TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.

CVSS3: 9.8
debian
около 6 лет назад

TUF (aka The Update Framework) through 0.12.1 has Improper Verificatio ...

EPSS

Процентиль: 41%
0.00195
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-347