Amazon tough是美国亚马逊(Amazon)公司的 一个The Update Framework(TUF) 存储库的 Rust 客户端库。 Amazon tough tough-v0.22.0之前版本存在数据伪造问题漏洞,该漏洞源于委托元数据验证中缺少过期、哈希和长度强制检查,可能导致具有委托签名权限的远程经过身份验证的用户绕过TUF规范完整性检查并污染本地元数据缓存。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-6911 | 9.8 CRITICAL | Authentication Bypass via Missing JWT Signature Verification in AWS Ops Wheel |
| CVE-2026-6912 | 8.8 HIGH | Privilege Escalation via Self-Writable Cognito Custom Attribute in AWS Ops Wheel |
| CVE-2026-6968 | 5.9 MEDIUM | Multiple Path Traversal Variants in awslabs/tough |
| CVE-2026-6966 | 5.3 MEDIUM | Signature Threshold Bypass in awslabs/tough Delegated Roles |
No comments yet