Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Terminating targets role delegations are not respected in tough
Vulnerability Description
Missing validation of terminating delegation causes the client to continue searching the defined delegation list, even after searching a terminating delegation. This could cause the client to fetch a target from an incorrect source, altering the target contents. Users should upgrade to tough version 0.20.0 or later and ensure any forked or derivative code is patched to incorporate the new fixes.
CVSS Information
N/A
Vulnerability Type
控制流实现总是不正确
Vulnerability Title
Amazon tough 安全漏洞
Vulnerability Description
Amazon tough是美国亚马逊(Amazon)公司的 一个The Update Framework(TUF) 存储库的 Rust 客户端库。 Amazon tough 0.20.0之前版本存在安全漏洞,该漏洞源于缺少对终止委托的验证,可能导致客户端从错误的源获取目标。
CVSS Information
N/A
Vulnerability Type
N/A