Количество 2
Количество 2
CVE-2025-2887
During a target rollback, the client fails to detect the rollback for delegated targets. This could cause the client to fetch a target from an incorrect source, altering the target contents. Users should upgrade to tough version 0.20.0 or later and ensure any forked or derivative code is patched to incorporate the new fixes.
GHSA-q6r9-r9pw-4cf7
tough failure to detect delegated target rollback
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-2887 During a target rollback, the client fails to detect the rollback for delegated targets. This could cause the client to fetch a target from an incorrect source, altering the target contents. Users should upgrade to tough version 0.20.0 or later and ensure any forked or derivative code is patched to incorporate the new fixes. | CVSS3: 4.5 | 0% Низкий | 11 месяцев назад | |
GHSA-q6r9-r9pw-4cf7 tough failure to detect delegated target rollback | CVSS3: 4.2 | 0% Низкий | 11 месяцев назад |
Уязвимостей на страницу