ZeroHour

CVE-2020-15163

CVSS 3.1
8.2 high
EPSS
<1%p50
Published
()
Modified
Description

Python TUF (The Update Framework) reference implementation before version 0.12 it will incorrectly trust a previously downloaded root metadata file which failed verification at download time. This allows an attacker who is able to serve multiple new versions of root metadata (i.e. by a person-in-the-middle attack) culminating in a version which has not been correctly signed to control the trust chain for future updates. This is fixed in version 0.12 and newer.

Vendors
linuxfoundation
Products
the update framework
Weakness
CWE-863, CWE-345
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.