VDB
Sign up
HIGH7.5

GHSA-hcwr-pq9g-rq3m

apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible)

Quick fix

GHSA-hcwr-pq9g-rq3m — chainguard.dev/apko: upgrade to the fixed version with the command below.

go get chainguard.dev/apko@v1.2.7

Details

apko verifies the signature on `APKINDEX.tar.gz` but never compares individually downloaded `.apk` packages against the checksum recorded in the signed index. The checksum is parsed and available via `ChecksumString()`, and the downloaded package control hash is computed, but the two values are never compared in `getPackageImpl()`. Mismatched packages are silently accepted. An attacker who can substitute download responses (compromised mirror, HTTP repository, poisoned CDN cache) can install arbitrary packages into built images.

**Fix:** No fix available yet.

**Acknowledgements**

apko thanks Oleh Konko from [1seal](https://1seal.org/) for discovering and reporting this issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/chainguard.dev/apko
Introduced in: 0Fixed in: 1.2.7
Fixgo get chainguard.dev/apko@v1.2.7

References