CVE-2020-15093

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-15093
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-15093.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-15093
Aliases
Published
2020-07-09T19:15:11Z
Modified
2024-10-12T06:10:24.889957Z
Severity
  • 8.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signatures. It allows an attacker to duplicate a valid signature in order to circumvent TUF requiring a minimum threshold of unique signatures before the metadata is considered valid. A fix is available in version 0.7.1. CVE-2020-6174 is assigned to the same vulnerability in the TUF reference implementation.

References

Affected packages

Git / github.com/awslabs/tough

Affected ranges

Type
GIT
Repo
https://github.com/awslabs/tough
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/theupdateframework/python-tuf
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

olpc-cjson-v0.*

olpc-cjson-v0.1.0
olpc-cjson-v0.1.1

tough-kms-v0.*

tough-kms-v0.1.0
tough-kms-v0.1.1
tough-kms-v0.2.0
tough-kms-v0.3.0
tough-kms-v0.3.1
tough-kms-v0.3.2
tough-kms-v0.3.3
tough-kms-v0.3.4
tough-kms-v0.3.5

tough-ssm-v0.*

tough-ssm-v0.1.0
tough-ssm-v0.2.0
tough-ssm-v0.3.0
tough-ssm-v0.4.0
tough-ssm-v0.5.0
tough-ssm-v0.6.0
tough-ssm-v0.6.1
tough-ssm-v0.6.2
tough-ssm-v0.6.3
tough-ssm-v0.6.4
tough-ssm-v0.6.5

tough-v0.*

tough-v0.1.0
tough-v0.10.0
tough-v0.11.0
tough-v0.11.1
tough-v0.11.2
tough-v0.11.3
tough-v0.12.0
tough-v0.12.1
tough-v0.2.0
tough-v0.3.0
tough-v0.4.0
tough-v0.5.0
tough-v0.6.0
tough-v0.7.0
tough-v0.7.1
tough-v0.8.0
tough-v0.9.0

tuftool-v0.*

tuftool-v0.1.0
tuftool-v0.1.1
tuftool-v0.2.0
tuftool-v0.3.0
tuftool-v0.4.0
tuftool-v0.4.1
tuftool-v0.5.0
tuftool-v0.6.0
tuftool-v0.6.1
tuftool-v0.6.2
tuftool-v0.6.3
tuftool-v0.6.4
tuftool-v0.7.0

v0.*

v0.10.0
v0.10.1
v0.10.2
v0.11.0
v0.11.1
v0.11.2.dev1
v0.11.2.dev2
v0.11.2.dev3
v0.12.0
v0.12.1
v0.7.5
v0.9.8
v0.9.9