Amazon tough是美国亚马逊(Amazon)公司的 一个The Update Framework(TUF) 存储库的 Rust 客户端库。 Amazon tough tough-v0.22.0之前版本存在数据伪造问题漏洞,该漏洞源于委托角色验证中加密签名唯一性验证不当,可能导致远程经过身份验证的用户通过复制有效签名绕过TUF签名阈值要求,导致客户端接受伪造的委托角色元数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-6911 | 9.8 CRITICAL | Authentication Bypass via Missing JWT Signature Verification in AWS Ops Wheel |
| CVE-2026-6912 | 8.8 HIGH | Privilege Escalation via Self-Writable Cognito Custom Attribute in AWS Ops Wheel |
| CVE-2026-6968 | 5.9 MEDIUM | Multiple Path Traversal Variants in awslabs/tough |
| CVE-2026-6967 | 5.9 MEDIUM | Missing Delegated Metadata Validation in awslabs/tough |
No comments yet