GHSA-3633-5h82-39pq
LOWIf an attacker is able to control a threshold of keys to insert the same public key more than once with different key IDs into signed, trusted metadata on a TUF repository, then go-tuf [clients](https://github.com/theupdateframework/go-tuf#client) < [0.3.2](https://github.com/theupdateframework/go-tuf/releases/tag/v0.3.2) are susceptible to an attack where attackers can cause the same signature fr
- Affected
- >=0, <0.3.2
- Fixed in
- not stated
- Weakness
- CWE-289
- Published
- 2022-09-16
- Source
- osv