CVE-2021-41150

Published
View on NVD ↗
CVSS v3
8.2
HIGH
CVSS v2
3.5
LOW
Affected
2
PROJECTS

Description

Tough provides a set of Rust libraries and tools for using and generating the update framework (TUF) repositories. The tough library, prior to 0.12.0, does not properly sanitize delegated role names when caching a repository, or when loading a repository from the filesystem. When the repository is cached or loaded, files ending with the .json extension could be overwritten with role metadata anywhere on the system. A fix is available in version 0.12.0. No workarounds to this issue are known.

Rust libraries and tools for using and generating TUF repositories
GitHubGitHub
224
Python reference implementation of The Update Framework (TUF)
GitHubGitHub
1.71K