—
GO-2022-0444
Version rollback attack in github.com/theupdateframework/go-tuf
Quick fix
GO-2022-0444 — github.com/theupdateframework/go-tuf: upgrade to the fixed version with the command below.
go get github.com/theupdateframework/go-tuf@v0.3.0Details
The TUF client is vulnerable to rollback attacks, in which an attacker causes a client to install software older than the software the client previously knew to be available.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/theupdateframework/go-tuf
Introduced in:
0Fixed in: 0.3.0Fix
go get github.com/theupdateframework/go-tuf@v0.3.0