Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-8628 | During a snapshot rollback, the client incorrectly caches the timestamp metadata. If the client checks the cache when attempting to perform the next update, the update timestamp validation will fail, preventing the next update until the cache is cleared. Users should upgrade to tough version 0.20.0 or later and ensure any forked or derivative code is patched to incorporate the new fixes. |
Github GHSA |
GHSA-76g3-38jv-wxh4 | tough timestamp metadata is cached when it fails snapshot rollback check |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 14 Oct 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 19 Sep 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amazon
Amazon tough |
|
| CPEs | cpe:2.3:a:amazon:tough:*:*:*:*:*:rust:*:* | |
| Vendors & Products |
Amazon
Amazon tough |
|
| Metrics |
cvssV3_1
|
Fri, 28 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Mar 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | During a snapshot rollback, the client incorrectly caches the timestamp metadata. If the client checks the cache when attempting to perform the next update, the update timestamp validation will fail, preventing the next update until the cache is cleared. Users should upgrade to tough version 0.20.0 or later and ensure any forked or derivative code is patched to incorporate the new fixes. | |
| Title | Improper timestamp caching during snapshot rollback in tough | |
| Weaknesses | CWE-1025 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2025-10-14T18:27:20.982Z
Reserved: 2025-03-27T21:08:16.138Z
Link: CVE-2025-2888
Updated: 2025-03-28T14:33:21.587Z
Status : Modified
Published: 2025-03-27T23:15:35.717
Modified: 2025-10-14T19:15:40.007
Link: CVE-2025-2888
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA