—
GO-2022-0326
Improper certificate validation in github.com/sigstore/cosign
Quick fix
GO-2022-0326 — github.com/sigstore/cosign: upgrade to the fixed version with the command below.
go get github.com/sigstore/cosign@v1.5.2Details
Cosign can be manipulated to claim that an entry for a signature in the OCI registry exists in the Rekor transparency log even if it does not. This requires the attacker to have pull and push permissions for the signature in OCI. This can happen with both standard signing with a keypair and "keyless signing" with Fulcio certificate authority.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/sigstore/cosign
Introduced in:
0Fixed in: 1.5.2Fix
go get github.com/sigstore/cosign@v1.5.2