PT-2025-13410 · Tough · Tough

Adamkorcz

+1

·

Published

2025-03-27

·

Updated

2025-03-29

·

CVE-2025-2887

CVSS v4.0

5.7

Medium

VectorAV:N/AC:H/AT:N/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions tough versions prior to 0.20.0
Description The issue arises during a target rollback when the client fails to detect the rollback for delegated targets, potentially causing it to fetch a target from an incorrect source and alter the target contents. This could lead to the client trusting and downloading outdated targets that it should reject.
Recommendations For versions prior to 0.20.0, upgrade to tough version 0.20.0 or later and ensure any forked or derivative code is patched to incorporate the new fixes.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-2887
GHSA-Q6R9-R9PW-4CF7

Affected Products

Tough