CVE-2021-41149: Improper sanitization of target names in tough
Tough provides a set of Rust libraries and tools for using and generating the update framework (TUF) repositories. The tough library, prior to 0.12.0, does not properly sanitize target names when caching a repository, or when saving specific targets to an output directory. When targets are cached or saved, files could be overwritten with arbitrary content anywhere on the system. A fix is available in version 0.12.0. No workarounds to this issue are known.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-41149?
CVE-2021-41149 is a vulnerability in the tough library, versions prior to 0.12.0, which does not properly sanitize target names when caching a repository or when saving specific targets to an output directory.
How does CVE-2021-41149 affect Amazon Tough?
CVE-2021-41149 affects Amazon Tough versions prior to 0.12.0.
What is the severity of CVE-2021-41149?
CVE-2021-41149 has a severity rating of 8.1 (high).
How can I fix CVE-2021-41149?
To fix CVE-2021-41149, users should update to version 0.12.0 or later of the tough library.
Where can I find more information about CVE-2021-41149?
You can find more information about CVE-2021-41149 on the GitHub page for awslabs/tough, as well as in the associated security advisory.