{"id":"RUSTSEC-2020-0024","summary":"Improper uniqueness verification of signature threshold","details":"The tough library, prior to 0.7.1, does not properly verify the uniqueness of\nkeys in the signatures provided to meet the threshold of cryptographic\nsignatures. It allows someone with access to a valid signing key to create\nmultiple valid signatures in order to circumvent TUF requiring a minimum\nthreshold of unique keys before the metadata is considered valid.\n\nAWS would like to thank Erick Tryzelaar of the Google Fuchsia Team for\nreporting this issue.\n\nA fix is available in version 0.7.1.\n\nCVE-2020-6174 is assigned to the same issue in the TUF reference\nimplementation.\n\nIf you have any questions or comments about this advisory, contact AWS Security\nat aws-security@amazon.com.","aliases":["CVE-2020-15093","GHSA-5q2r-92f9-4m49"],"modified":"2026-02-04T02:21:11.162402Z","published":"2020-07-09T12:00:00Z","related":["CVE-2020-6174"],"database_specific":{"license":"CC0-1.0"},"references":[{"type":"PACKAGE","url":"https://crates.io/crates/tough"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2020-0024.html"},{"type":"ADVISORY","url":"https://github.com/awslabs/tough/security/advisories/GHSA-5q2r-92f9-4m49"}],"affected":[{"package":{"name":"tough","ecosystem":"crates.io","purl":"pkg:cargo/tough"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.0-0"},{"fixed":"0.7.1"}]}],"ecosystem_specific":{"affects":{"functions":[],"os":[],"arch":[]},"affected_functions":null},"database_specific":{"cvss":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N","informational":null,"source":"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2020-0024.json","categories":[]}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N"}]}