7.0.1
12 years ago
15 days ago
Known vulnerabilities in the tuf package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
tuf is a secure updater framework for Python. Affected versions of this package are vulnerable to Improper Handling of Case Sensitivity due to platform-dependent behavior in the Note: This is only exploitable if the client is running on Windows, the repository contains delegations with path patterns differing only in case, and the attacker-controlled role is visited before the legitimate role in the delegation order. How to fix Improper Handling of Case Sensitivity? Upgrade | [,7.0.0) |
tuf is a secure updater framework for Python. Affected versions of this package are vulnerable to Directory Traversal during a call to How to fix Directory Traversal? Upgrade | [,0.19.0) |
tuf is a secure updater framework for Python. Affected versions of this package are vulnerable to Improper Authorization. It will incorrectly trust a previously downloaded root metadata file which failed verification at download time. This allows an attacker who is able to serve multiple new versions of root metadata (i.e. by a person-in-the-middle attack) culminating in a version which has not been correctly signed to control the trust chain for future updates. How to fix Improper Authorization? Upgrade | [,0.12) |
tuf is a secure updater framework for Python. Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature. The metadadata signature verification as provided by How to fix Improper Verification of Cryptographic Signature? Upgrade | [,0.12.2) |
tuf is a secure updater framework for Python. Affected versions of this package are vulnerable to Denial of Service (DoS). While maximum file size is restricted for downloading, the client may attempt to validate a large number of signatures. The file size limit of How to fix Denial of Service (DoS)? Upgrade | [0.7.2,0.12.2) |