CVE-2025-2888

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Mar 27, 2025
Updated: Mar 28, 2025
CWE ID 79

Summary

CVE-2025-2888 is a vulnerability affecting snapshot rollbacks in certain versions of the Tough data integrity tool. The issue lies in the incorrect caching of timestamp metadata during rollbacks. If the client relies on the cache for the next update, the update timestamp validation will fail, leading to the prevention of further updates until the cache is cleared. To mitigate this risk, users must upgrade to Tough version 0.20.0 or later and ensure any forked or derivative code is patched with the new fixes.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share