PT-2025-13406 · Tough · Tough

Adamkorcz

+1

·

Published

2025-03-27

·

Updated

2025-03-29

·

CVE-2025-2885

CVSS v4.0

5.7

Medium

VectorAV:N/AC:H/AT:N/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions tough versions prior to 0.20.0
Description The issue arises from missing validation of the root metadata version number, allowing an actor to supply an arbitrary version number to the client. This could lead to the client trusting an outdated or rotated root role, potentially trusting content associated with a previous root role. Users should upgrade to a version that incorporates the new fixes to prevent this issue.
Recommendations For versions prior to 0.20.0, upgrade to tough version 0.20.0 or later and ensure any forked or derivative code is patched to incorporate the new fixes.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-2885
GHSA-5VMP-M5V2-HX47

Affected Products

Tough