Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r56q-vv3c-6g9c

Опубликовано: 19 окт. 2021
Источник: github
Github: Прошло ревью
CVSS3: 8.2

Описание

Improper sanitization of delegated role names

Impact

The tough library, prior to 0.12.0, does not properly sanitize delegated role names when caching a repository, or when loading a repository from the filesystem. When the repository is cached or loaded, files ending with the .json extension could be overwritten with role metadata anywhere on the system.

AWS would like to thank https://github.com/jku for reporting this issue.

Patches

A fix is available in version 0.12.0.

Workarounds

No workarounds to this issue are known.

References

https://github.com/theupdateframework/python-tuf/security/advisories/GHSA-wjw6-2cqr-j4qr

Пакеты

Наименование

tough

rust
Затронутые версииВерсия исправления

< 0.12.0

0.12.0

EPSS

Процентиль: 66%
0.00524
Низкий

8.2 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.2
nvd
больше 4 лет назад

Tough provides a set of Rust libraries and tools for using and generating the update framework (TUF) repositories. The tough library, prior to 0.12.0, does not properly sanitize delegated role names when caching a repository, or when loading a repository from the filesystem. When the repository is cached or loaded, files ending with the .json extension could be overwritten with role metadata anywhere on the system. A fix is available in version 0.12.0. No workarounds to this issue are known.

EPSS

Процентиль: 66%
0.00524
Низкий

8.2 High

CVSS3

Дефекты

CWE-22