Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. tuf
  4. ›
  5. CVE-2020-6173

CVE-2020-6173: Client Denial of Service on TUF

August 21, 2020 (updated November 18, 2024)

An attacker who can gain file access to the repository and modify metadata files may cause a denial of service to clients by creating many invalid signatures on a metadata file. Having a large number of signatures to verify will delay the moment when the client will determine the signature is not valid. This delay may be for at least a few minutes, but possibly could be longer especially if multiple files are impacted.

The tuf maintainers would like to thank Erik MacLean of Analog Devices, Inc. for reporting this issue.

References

  • github.com/advisories/GHSA-2828-9vh6-9m6j
  • github.com/pypa/advisory-database/tree/main/vulns/tuf/PYSEC-2020-146.yaml
  • github.com/theupdateframework/tuf
  • github.com/theupdateframework/tuf/commits/develop
  • github.com/theupdateframework/tuf/issues/973
  • github.com/theupdateframework/tuf/security/advisories/GHSA-2828-9vh6-9m6j
  • nvd.nist.gov/vuln/detail/CVE-2020-6173

Code Behaviors & Features

Detect and mitigate CVE-2020-6173 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 0.7.2 before 0.12.2

Fixed versions

  • 0.12.2

Solution

Upgrade to version 0.12.2 or above.

Impact 5.3 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Learn more about CVSS

Weakness

  • CWE-400: Uncontrolled Resource Consumption

Source file

pypi/tuf/CVE-2020-6173.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:15 +0000.