VYPR

The Update Framework

by Linux Foundation

CVEs (4)

  • CVE-2020-6174CriFeb 5, 2020
    risk 0.57cvss 9.8epss 0.01

    TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.

  • CVE-2020-15163HigSep 9, 2020
    risk 0.50cvss 8.7epss 0.01

    Python TUF (The Update Framework) reference implementation before version 0.12 it will incorrectly trust a previously downloaded root metadata file which failed verification at download time. This allows an attacker who is able to serve multiple new versions of root metadata…

  • CVE-2021-41131HigOct 19, 2021
    risk 0.42cvss 7.5epss 0.01

    python-tuf is a Python reference implementation of The Update Framework (TUF). In both clients (`tuf/client` and `tuf/ngclient`), there is a path traversal vulnerability that in the worst case can overwrite files ending in `.json` anywhere on the client system on a call to…

  • CVE-2020-6173MedJan 14, 2020
    risk 0.35cvss 5.3epss 0.02

    TUF (aka The Update Framework) 0.7.2 through 0.12.1 allows Uncontrolled Resource Consumption.