theupdateframework kayıtları
theupdateframework üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-347 Improper Verification of Cryptographic Signature1
- CWE-354 Improper Validation of Integrity Check Value1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-617 Reachable Assertion1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2022-29173İstismar yok | No protection against rollback attacks in go-tuftheupdateframework · go-tuf · CWE-354 | Yüksek8,8 | — | %0,6 | 5 May 2022 |
32İzleyin | CVE-2024-47534İstismar yok | Incorrect delegation lookups can make go-tuf download the wrong artifacttheupdateframework · go-tuf · CWE-362 | Yüksek8,2 | — | %0,5 | 1 Eki 2024 |
30İzleyin | CVE-2026-23991İstismar yok | go-tuf affected by client DoS via malformed server responsetheupdateframework · go-tuf · CWE-617 | Yüksek7,5 | — | %0,6 | 21 Oca 2026 |
30İzleyin | CVE-2026-23992İstismar yok | go-tuf improperly validates the configured threshold for delegationstheupdateframework · go-tuf · CWE-347 | Yüksek7,5 | — | %0,2 | 21 Oca 2026 |
18İzleyin | CVE-2026-24686İstismar yok | go-tuf Path Traversal in TAP 4 Multirepo Client Allows Arbitrary File Write via Malicious Repository Namestheupdateframework · go-tuf · CWE-22 | Orta4,7 | — | %0,2 | 26 Oca 2026 |
- CVE-2022-2917335İzleyin
No protection against rollback attacks in go-tuf
YüksekCVSS 8,8İstismar yokEPSS %1theupdateframework · go-tuf5 May 2022
- CVE-2024-4753432İzleyin
Incorrect delegation lookups can make go-tuf download the wrong artifact
YüksekCVSS 8,2İstismar yokEPSS %1theupdateframework · go-tuf1 Eki 2024
- CVE-2026-2399130İzleyin
go-tuf affected by client DoS via malformed server response
YüksekCVSS 7,5İstismar yokEPSS %1theupdateframework · go-tuf21 Oca 2026
- CVE-2026-2399230İzleyin
go-tuf improperly validates the configured threshold for delegations
YüksekCVSS 7,5İstismar yokEPSS %0theupdateframework · go-tuf21 Oca 2026
- CVE-2026-2468618İzleyin
go-tuf Path Traversal in TAP 4 Multirepo Client Allows Arbitrary File Write via Malicious Repository Names
OrtaCVSS 4,7İstismar yokEPSS %0theupdateframework · go-tuf26 Oca 2026