Path traversal in tough - CVE-2021-41150
Published: October 19, 2021 / Updated: April 25, 2026
tough
Amazon Web Services
Description
The vulnerability allows a local user to overwrite arbitrary .json files on the system.
The vulnerability exists due to improper sanitization of delegated role names in repository caching and filesystem loading logic when caching a repository or loading a repository from the filesystem. A local user can use crafted delegated role names to overwrite arbitrary .json files on the system.