CVE-2020-15093

Published
View on NVD ↗
CVSS v3
8.6
HIGH
CVSS v2
5
MEDIUM
Affected
3
PROJECTS

Description

The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signatures. It allows an attacker to duplicate a valid signature in order to circumvent TUF requiring a minimum threshold of unique signatures before the metadata is considered valid. A fix is available in version 0.7.1. CVE-2020-6174 is assigned to the same vulnerability in the TUF reference implementation.

Rust libraries and tools for using and generating TUF repositories
GitHubGitHub
224
Python reference implementation of The Update Framework (TUF)
GitHubGitHub
1.71K
The Update Framework (TUF) repository client
Crates.ioCrates.io
1.67M