Логотип exploitDog
bind:CVE-2020-15093
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-15093

Количество 2

Количество 2

nvd логотип

CVE-2020-15093

больше 5 лет назад

The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signatures. It allows an attacker to duplicate a valid signature in order to circumvent TUF requiring a minimum threshold of unique signatures before the metadata is considered valid. A fix is available in version 0.7.1. CVE-2020-6174 is assigned to the same vulnerability in the TUF reference implementation.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-5q2r-92f9-4m49

больше 4 лет назад

Improper verification of signature threshold in tough

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-15093

The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signatures. It allows an attacker to duplicate a valid signature in order to circumvent TUF requiring a minimum threshold of unique signatures before the metadata is considered valid. A fix is available in version 0.7.1. CVE-2020-6174 is assigned to the same vulnerability in the TUF reference implementation.

CVSS3: 8.6
0%
Низкий
больше 5 лет назад
github логотип
GHSA-5q2r-92f9-4m49

Improper verification of signature threshold in tough

CVSS3: 8.6
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу