Metrics
Affected Vendors & Products
Fri, 22 Nov 2024 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 11 Oct 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Wed, 02 Oct 2024 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Tue, 01 Oct 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Theupdateframework
Theupdateframework go-tuf |
|
CPEs | cpe:2.3:a:theupdateframework:go-tuf:*:*:*:*:*:*:*:* | |
Vendors & Products |
Theupdateframework
Theupdateframework go-tuf |
|
Metrics |
cvssV3_1
|
Tue, 01 Oct 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | go-tuf is a Go implementation of The Update Framework (TUF). The go-tuf client inconsistently traces the delegations. For example, if targets delegate to "A", and to "B", and "B" delegates to "C", then the client should trace the delegations in the order "A" then "B" then "C" but it may incorrectly trace the delegations "B"->"C"->"A". This vulnerability is fixed in 2.0.1. | |
Title | Incorrect delegation lookups can make go-tuf download the wrong artifact | |
Weaknesses | CWE-362 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-11-21T16:56:38.062Z
Reserved: 2024-09-25T21:46:10.929Z
Link: CVE-2024-47534

Updated: 2024-10-01T17:16:08.804Z

Status : Awaiting Analysis
Published: 2024-10-01T16:15:09.857
Modified: 2024-11-21T17:15:17.047
Link: CVE-2024-47534
