CVE-2020-15163 affects the Python TUF (The Update Framework) reference implementation prior to version 0.12. It allows an attacker to control the trust chain for future updates by exploiting a flaw where previously downloaded, but failed-to-verify, root metadata files are incorrectly trusted. This vulnerability carries a high CVSS score of 8.2 due to its network attack vector, high impact on confidentiality and integrity, and the potential for a sophisticated attacker to perform a man-in-the-middle attack. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.12.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:the_update_framework:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.