—
PYSEC-2020-145
Quick fix
PYSEC-2020-145 — tuf: upgrade to the fixed version with the command below.
pip install --upgrade 'tuf>=3d342e648fbacdf43a13d7ba8886aaaf07334af7'Details
Python TUF (The Update Framework) reference implementation before version 0.12 it will incorrectly trust a previously downloaded root metadata file which failed verification at download time. This allows an attacker who is able to serve multiple new versions of root metadata (i.e. by a person-in-the-middle attack) culminating in a version which has not been correctly signed to control the trust chain for future updates. This is fixed in version 0.12 and newer.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/tuf
Introduced in:
0Fixed in: 3d342e648fbacdf43a13d7ba8886aaaf07334af7Fix
pip install --upgrade 'tuf>=3d342e648fbacdf43a13d7ba8886aaaf07334af7'References
- https://github.com/theupdateframework/tuf/releases/tag/v0.12.0[WEB]
- https://github.com/theupdateframework/tuf/security/advisories/GHSA-f8mr-jv2c-v8mg[ADVISORY]
- https://github.com/theupdateframework/tuf/commit/3d342e648fbacdf43a13d7ba8886aaaf07334af7[FIX]
- https://pypi.org/project/tuf[PACKAGE]
- https://github.com/theupdateframework/tuf/pull/885[WEB]