Rollback Vulnerability in Tough Client by AWS
CVE-2025-2887
What is CVE-2025-2887?
The Tough client by AWS contains a vulnerability that arises during the process of rolling back to a target. This flaw prevents the client from accurately detecting the rollback for delegated targets, potentially allowing the client to retrieve a target from an incorrect source. As a result, this could lead to unintended alterations in the contents of the target. To mitigate this risk, users are urged to upgrade to Tough version 0.20.0 or later and ensure that any forked or derivative code is updated with the latest patches to incorporate the necessary fixes.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
tough 0.1.0 < 0.20.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
