PT-2025-13406 · Tough · Tough
Adamkorcz
+1
·
Published
2025-03-27
·
Updated
2025-03-29
·
CVE-2025-2885
CVSS v4.0
5.7
Medium
| Vector | AV:N/AC:H/AT:N/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
tough versions prior to 0.20.0
Description
The issue arises from missing validation of the root metadata version number, allowing an actor to supply an arbitrary version number to the client. This could lead to the client trusting an outdated or rotated root role, potentially trusting content associated with a previous root role. Users should upgrade to a version that incorporates the new fixes to prevent this issue.
Recommendations
For versions prior to 0.20.0, upgrade to tough version 0.20.0 or later and ensure any forked or derivative code is patched to incorporate the new fixes.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tough