The Update Framework
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-6174 | Cri | 0.57 | 9.8 | 0.01 | Feb 5, 2020 | TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature. | ||
| CVE-2020-15163 | Hig | 0.50 | 8.7 | 0.01 | Sep 9, 2020 | Python TUF (The Update Framework) reference implementation before version 0.12 it will incorrectly trust a previously downloaded root metadata file which failed verification at download time. This allows an attacker who is able to serve multiple new versions of root metadata… | ||
| CVE-2021-41131 | Hig | 0.42 | 7.5 | 0.01 | Oct 19, 2021 | python-tuf is a Python reference implementation of The Update Framework (TUF). In both clients (`tuf/client` and `tuf/ngclient`), there is a path traversal vulnerability that in the worst case can overwrite files ending in `.json` anywhere on the client system on a call to… | ||
| CVE-2020-6173 | Med | 0.35 | 5.3 | 0.02 | Jan 14, 2020 | TUF (aka The Update Framework) 0.7.2 through 0.12.1 allows Uncontrolled Resource Consumption. |
- risk 0.57cvss 9.8epss 0.01
TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.
- risk 0.50cvss 8.7epss 0.01
Python TUF (The Update Framework) reference implementation before version 0.12 it will incorrectly trust a previously downloaded root metadata file which failed verification at download time. This allows an attacker who is able to serve multiple new versions of root metadata…
- risk 0.42cvss 7.5epss 0.01
python-tuf is a Python reference implementation of The Update Framework (TUF). In both clients (`tuf/client` and `tuf/ngclient`), there is a path traversal vulnerability that in the worst case can overwrite files ending in `.json` anywhere on the client system on a call to…
- risk 0.35cvss 5.3epss 0.02
TUF (aka The Update Framework) 0.7.2 through 0.12.1 allows Uncontrolled Resource Consumption.