CVE-2024-47534
Trivy vulnerability analysis and mitigation

Overview

The go-tuf client, a Go implementation of The Update Framework (TUF), contains a vulnerability in its delegation tracing functionality. The vulnerability was discovered during testing with the TUF conformance test suite and affects versions up to and including v2.0.0. The issue was fixed in version 2.0.1 (GitHub Advisory).

Technical details

The vulnerability stems from inconsistent delegation tracing in the go-tuf client. For example, if targets delegate to 'A' and 'B', and 'B' delegates to 'C', the client should trace the delegations in the order 'A' then 'B' then 'C'. However, due to the bug, it may incorrectly trace the delegations as 'B'->'C'->'A'. The root cause was identified in the GetRolesForTarget function, which returns an unordered map instead of an ordered list, leading to inconsistent delegation traversal (GitHub Advisory).

Impact

The incorrect delegation tracing can result in the client downloading wrong artifacts, potentially leading to security implications in software update systems. This vulnerability has been assigned a High severity rating, as it could affect the integrity of software updates (GitHub Advisory).

Mitigation and workarounds

Users should upgrade to go-tuf version 2.0.1 or later, which contains the fix for this vulnerability. The fix involves modifying the GetRolesForTarget function to return an ordered list instead of an unordered map (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Trivy vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-25621HIGH7.8
  • DockerDocker
  • helm-4
NoYesNov 06, 2025
CVE-2025-58187HIGH7.5
  • cAdvisorcAdvisor
  • rootlesskit
NoYesOct 29, 2025
CVE-2025-52881HIGH7.3
  • cAdvisorcAdvisor
  • kernel-abi-stablelists
NoYesNov 06, 2025
CVE-2025-64329MEDIUM6.9
  • DockerDocker
  • linkerd2
NoYesNov 07, 2025
CVE-2025-58181MEDIUM5.3
  • cAdvisorcAdvisor
  • fluent-bit-plugin-loki
NoYesNov 19, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management