Back to search
CVE-2025-8454
Published: Aug 1, 2025
Modified: Aug 1, 2025
PUBLISHED
Description
It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification if the upstream source is already downloaded from a previous run even if the verification failed back then.
| Vendor | Product | Versions |
|---|---|---|
Debian | devscripts | affected 0 |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now