QID 980723
QID 980723: Python (pip) Security Update for tuf (GHSA-pwqf-9h7j-7mv8)
Security update has been released for tuf to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Metadadata signature verification, as used in `tuf.client.updater`, counted each of multiple signatures with identical authorized keyids separately towards the threshold. Therefore, an attacker with access to a valid signing key could create multiple valid signatures in order to meet the minimum threshold of keys before the metadata was considered valid.
The tuf maintainers would like to thank Erik MacLean of Analog Devices, Inc. for reporting this issue.
Solution
A [fix](https://github.com/theupdateframework/tuf/pull/974) is available in version [0.12.2](https://github.com/theupdateframework/tuf/releases/tag/v0.12.2) or newer.Workaround:
No workarounds are known for this issue.
No workarounds are known for this issue.
Vendor References
- GHSA-pwqf-9h7j-7mv8 -
github.com/advisories/GHSA-pwqf-9h7j-7mv8
CVEs related to QID 980723
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-pwqf-9h7j-7mv8 | tuf |
|