Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
go-tuf improperly validates the configured threshold for delegations
Vulnerability Description
go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF repository can have the configured value of signature thresholds set to 0, which effectively disables signature verification. This can lead to unauthorized modification to TUF metadata files is possible at rest, or during transit as no integrity checks are made. Version 2.3.1 fixes the issue. As a workaround, always make sure that the TUF metadata roles are configured with a threshold of at least 1.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
密码学签名的验证不恰当
Vulnerability Title
go-tuf 数据伪造问题漏洞
Vulnerability Description
go-tuf是The Update Framework开源的一个用于保护软件更新系统的框架。 go-tuf 2.0.0版本至2.3.1之前版本存在数据伪造问题漏洞,该漏洞源于签名阈值配置不当,可能导致对TUF元数据文件的未授权修改。
CVSS Information
N/A
Vulnerability Type
N/A