VDB
Sign up
—

GO-2022-0326

Improper certificate validation in github.com/sigstore/cosign

Quick fix

GO-2022-0326 — github.com/sigstore/cosign: upgrade to the fixed version with the command below.

go get github.com/sigstore/cosign@v1.5.2

Details

Cosign can be manipulated to claim that an entry for a signature in the OCI registry exists in the Rekor transparency log even if it does not. This requires the attacker to have pull and push permissions for the signature in OCI. This can happen with both standard signing with a keypair and "keyless signing" with Fulcio certificate authority.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/sigstore/cosign
Introduced in: 0Fixed in: 1.5.2
Fixgo get github.com/sigstore/cosign@v1.5.2

References