Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x3r5-q6mj-m485

Опубликовано: 19 окт. 2021
Источник: github
Github: Прошло ревью
CVSS3: 8.2

Описание

Improper sanitization of target names

Impact

The tough library, prior to 0.12.0, does not properly sanitize target names when caching a repository, or when saving specific targets to an output directory. When targets are cached or saved, files could be overwritten with arbitrary content anywhere on the system.

AWS would like to thank https://github.com/jku for reporting this issue.

Patches

A fix is available in version 0.12.0.

Workarounds

No workarounds to this issue are known.

Пакеты

Наименование

tough

rust
Затронутые версииВерсия исправления

< 0.12.0

0.12.0

EPSS

Процентиль: 74%
0.00851
Низкий

8.2 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.2
nvd
больше 4 лет назад

Tough provides a set of Rust libraries and tools for using and generating the update framework (TUF) repositories. The tough library, prior to 0.12.0, does not properly sanitize target names when caching a repository, or when saving specific targets to an output directory. When targets are cached or saved, files could be overwritten with arbitrary content anywhere on the system. A fix is available in version 0.12.0. No workarounds to this issue are known.

EPSS

Процентиль: 74%
0.00851
Низкий

8.2 High

CVSS3

Дефекты

CWE-22