Amazon
Amazon Tough: vulnerabilidades y CVE
Amazon Tough tiene 10 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses3
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-6968 | Alta (7.1) | 0.64% | — | 24 abr 2026 | Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write files outside intended output directories via absolute target names in… |
| CVE-2026-6967 | Alta (7.1) | 0.30% | — | 24 abr 2026 | Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users with delegated signing authority to bypass TUF specification… |
| CVE-2026-6966 | Alta (7) | 0.37% | — | 24 abr 2026 | Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users to bypass the TUF signature threshold requirement by… |
| CVE-2025-2888 | Media (5.7) | 0.33% | — | 27 mar 2025 | During a snapshot rollback, the client incorrectly caches the timestamp metadata. If the client checks the cache when attempting to perform the next update, the update timestamp validation will fail, preventing the next… |
| CVE-2025-2887 | Media (5.7) | 0.33% | — | 27 mar 2025 | During a target rollback, the client fails to detect the rollback for delegated targets. This could cause the client to fetch a target from an incorrect source, altering the target contents. Users should upgrade to… |
| CVE-2025-2886 | Media (5.7) | 0.33% | — | 27 mar 2025 | Missing validation of terminating delegation causes the client to continue searching the defined delegation list, even after searching a terminating delegation. This could cause the client to fetch a target from an… |
| CVE-2025-2885 | Media (5.7) | 0.33% | — | 27 mar 2025 | Missing validation of the root metatdata version number could allow an actor to supply an arbitrary version number to the client instead of the intended version in the root metadata file, altering the version fetched by… |
| CVE-2021-41150 | Media (6.5) | 1.3% | — | 19 oct 2021 | Tough provides a set of Rust libraries and tools for using and generating the update framework (TUF) repositories. The tough library, prior to 0.12.0, does not properly sanitize delegated role names when caching a… |
| CVE-2021-41149 | Alta (8.1) | 1.1% | — | 19 oct 2021 | Tough provides a set of Rust libraries and tools for using and generating the update framework (TUF) repositories. The tough library, prior to 0.12.0, does not properly sanitize target names when caching a repository,… |
| CVE-2020-15093 | Alta (8.6) | 1.4% | — | 9 jul 2020 | The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signatures. It allows an attacker to duplicate a valid signature in order to circumvent TUF requiring a… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.