Записи theupdateframework
5 опубликованных записей вендора theupdateframework.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-347 Improper Verification of Cryptographic Signature1
- CWE-354 Improper Validation of Integrity Check Value1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-617 Reachable Assertion1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2022-29173Эксплойта нет | No protection against rollback attacks in go-tuftheupdateframework · go-tuf · CWE-354 | Высокая8,8 | — | 0,6 % | 5 мая 2022 г. |
32Наблюдать | CVE-2024-47534Эксплойта нет | Incorrect delegation lookups can make go-tuf download the wrong artifacttheupdateframework · go-tuf · CWE-362 | Высокая8,2 | — | 0,5 % | 1 окт. 2024 г. |
30Наблюдать | CVE-2026-23991Эксплойта нет | go-tuf affected by client DoS via malformed server responsetheupdateframework · go-tuf · CWE-617 | Высокая7,5 | — | 0,6 % | 21 янв. 2026 г. |
30Наблюдать | CVE-2026-23992Эксплойта нет | go-tuf improperly validates the configured threshold for delegationstheupdateframework · go-tuf · CWE-347 | Высокая7,5 | — | 0,2 % | 21 янв. 2026 г. |
18Наблюдать | CVE-2026-24686Эксплойта нет | go-tuf Path Traversal in TAP 4 Multirepo Client Allows Arbitrary File Write via Malicious Repository Namestheupdateframework · go-tuf · CWE-22 | Средняя4,7 | — | 0,2 % | 26 янв. 2026 г. |
- CVE-2022-2917335Наблюдать
No protection against rollback attacks in go-tuf
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %theupdateframework · go-tuf5 мая 2022 г.
- CVE-2024-4753432Наблюдать
Incorrect delegation lookups can make go-tuf download the wrong artifact
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %theupdateframework · go-tuf1 окт. 2024 г.
- CVE-2026-2399130Наблюдать
go-tuf affected by client DoS via malformed server response
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %theupdateframework · go-tuf21 янв. 2026 г.
- CVE-2026-2399230Наблюдать
go-tuf improperly validates the configured threshold for delegations
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %theupdateframework · go-tuf21 янв. 2026 г.
- CVE-2026-2468618Наблюдать
go-tuf Path Traversal in TAP 4 Multirepo Client Allows Arbitrary File Write via Malicious Repository Names
СредняяCVSS 4,7Эксплойта нетEPSS 0 %theupdateframework · go-tuf26 янв. 2026 г.