Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-47534

Опубликовано: 01 окт. 2024
Источник: nvd
EPSS Низкий

Описание

go-tuf is a Go implementation of The Update Framework (TUF). The go-tuf client inconsistently traces the delegations. For example, if targets delegate to "A", and to "B", and "B" delegates to "C", then the client should trace the delegations in the order "A" then "B" then "C" but it may incorrectly trace the delegations "B"->"C"->"A". This vulnerability is fixed in 2.0.1.

EPSS

Процентиль: 48%
0.0025
Низкий

Дефекты

CWE-362

Связанные уязвимости

ubuntu
больше 1 года назад

go-tuf is a Go implementation of The Update Framework (TUF). The go-tuf client inconsistently traces the delegations. For example, if targets delegate to "A", and to "B", and "B" delegates to "C", then the client should trace the delegations in the order "A" then "B" then "C" but it may incorrectly trace the delegations "B"->"C"->"A". This vulnerability is fixed in 2.0.1.

debian
больше 1 года назад

go-tuf is a Go implementation of The Update Framework (TUF). The go-tu ...

CVSS3: 7.5
github
больше 1 года назад

Incorrect delegation lookups can make go-tuf download the wrong artifact

suse-cvrf
больше 1 года назад

Security update for govulncheck-vulndb

EPSS

Процентиль: 48%
0.0025
Низкий

Дефекты

CWE-362