Improper Verification of Cryptographic Signature in tough - CVE-2020-15093
Published: July 9, 2020 / Updated: April 25, 2026
tough
Amazon Web Services
Description
The vulnerability allows a remote user to bypass signature threshold verification.
The vulnerability exists due to improper uniqueness verification of cryptographic signatures in signature threshold verification when validating signed metadata. A remote user can provide multiple valid signatures generated with the same signing key to bypass signature threshold verification.
Exploitation requires access to a valid signing key.