
Cloud Vulnerability DB
A community-led vulnerabilities database
The tough library (Rust/crates.io) prior to version 0.7.1 contains a vulnerability in the verification of cryptographic signature thresholds. The vulnerability was discovered and disclosed on July 9, 2020, and affects all versions before 0.7.1. The issue was reported by Erick Tryzelaar of the Google Fuchsia Team to AWS (AWS Advisory).
The vulnerability stems from improper verification of the uniqueness of keys in the signatures provided to meet the threshold of cryptographic signatures. The issue allows duplicate signatures from the same key to be counted multiple times toward the signature threshold requirement. This vulnerability has been assigned a CVSS v3.1 Base Score of 8.6 HIGH with vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N (NVD).
The vulnerability allows an attacker with access to a valid signing key to create multiple valid signatures to circumvent TUF's minimum threshold requirement for unique signatures before metadata is considered valid. This effectively undermines the security model of requiring multiple unique signatures for validation (AWS Advisory).
An attacker who has access to a valid signing key can exploit this vulnerability by creating multiple signatures with the same key. This bypasses the intended security measure of requiring multiple unique keys for signature validation (AWS Advisory).
A fix is available in version 0.7.1 of the tough library. Users should upgrade to this version or later to address the vulnerability. No alternative workarounds are known for this issue (AWS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."