Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-8454

Опубликовано: 01 авг. 2025
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification if the upstream source is already downloaded from a previous run even if the verification failed back then.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:debian:devscripts:2.25.15:*:*:*:*:*:*:*

EPSS

Процентиль: 4%
0.00022
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 9.8
ubuntu
24 дня назад

It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification if the upstream source is already downloaded from a previous run even if the verification failed back then.

CVSS3: 9.8
debian
24 дня назад

It was discovered that uscan, a tool to scan/watch upstream sources fo ...

CVSS3: 9.8
github
24 дня назад

It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification for files already downloaded even if a previous verification did fail.

EPSS

Процентиль: 4%
0.00022
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-347