{"id":"CVE-2020-6174","details":"TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.","aliases":["GHSA-pwqf-9h7j-7mv8","PYSEC-2020-147"],"modified":"2026-04-10T04:26:28.044498Z","published":"2020-02-05T16:15:11.457Z","related":["RUSTSEC-2020-0024"],"references":[{"type":"FIX","url":"https://github.com/theupdateframework/tuf/pull/974"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/theupdateframework/tuf","events":[{"introduced":"0"},{"last_affected":"25e9e77dad164116f6fefb24c026bd83484b85f3"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"0.12.1"}]}}],"versions":["v0.10.0","v0.10.2","v0.11.0","v0.11.1","v0.11.2.dev1","v0.11.2.dev2","v0.11.2.dev3","v0.12.0","v0.12.1","v0.7.5","v0.9.8","v0.9.9"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-6174.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}