VDB
Sign up
—

PYSEC-2020-145

Quick fix

PYSEC-2020-145 — tuf: upgrade to the fixed version with the command below.

pip install --upgrade 'tuf>=3d342e648fbacdf43a13d7ba8886aaaf07334af7'

Details

Python TUF (The Update Framework) reference implementation before version 0.12 it will incorrectly trust a previously downloaded root metadata file which failed verification at download time. This allows an attacker who is able to serve multiple new versions of root metadata (i.e. by a person-in-the-middle attack) culminating in a version which has not been correctly signed to control the trust chain for future updates. This is fixed in version 0.12 and newer.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/tuf
Introduced in: 0Fixed in: 3d342e648fbacdf43a13d7ba8886aaaf07334af7
Fixpip install --upgrade 'tuf>=3d342e648fbacdf43a13d7ba8886aaaf07334af7'

References