MEDIUM
Failure to detect delegated target rollback in tough
Published Mar 27, 2025
5.7
MEDIUMCVSS 4.0
EPSS 0.33%
Description
During a target rollback, the client fails to detect the rollback for delegated targets. This could cause the client to fetch a target from an incorrect source, altering the target contents. Users should upgrade to tough version 0.20.0 or later and ensure any forked or derivative code is patched to incorporate the new fixes.
Affected products
-
- Version 0.1.0StatusaffectedConstraints<0.20.0
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://aws.amazon.com/security/security-bulletins/AWS-2025-007 vendor-advisoryVendor Advisory
- https://github.com/advisories/GHSA-q6r9-r9pw-4cf7 Advisory
- https://github.com/awslabs/tough/commit/3345151a87c358d1ce43aeb7e8b3ebea5ebdbab4
- https://github.com/awslabs/tough/releases/tag/tough-v0.20.0 patch
- https://github.com/awslabs/tough/security/advisories/GHSA-q6r9-r9pw-4cf7 vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-2887
| Link | Providers | Tags |
|---|---|---|
| https://aws.amazon.com/security/security-bulletins/AWS-2025-007 | vendor-advisoryVendor Advisory | |
| https://github.com/advisories/GHSA-q6r9-r9pw-4cf7 | Advisory | |
| https://github.com/awslabs/tough/commit/3345151a87c358d1ce43aeb7e8b3ebea5ebdbab4 | ||
| https://github.com/awslabs/tough/releases/tag/tough-v0.20.0 | patch | |
| https://github.com/awslabs/tough/security/advisories/GHSA-q6r9-r9pw-4cf7 | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-2887 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner AMZN
Published Mar 27, 2025
Updated Oct 14, 2025
Reserved Mar 27, 2025
Link CVE-2025-2887
CISA Vulnrichment
GHSA-Q6R9-R9PW-4CF7 Updated Mar 28, 2025