—
GO-2023-2332
Gitsign's Rekor public keys fetched from upstream API instead of local TUF client. in github.com/sigstore/gitsign
Quick fix
GO-2023-2332 — github.com/sigstore/gitsign: upgrade to the fixed version with the command below.
go get github.com/sigstore/gitsign@v0.8.0Details
Gitsign's Rekor public keys fetched from upstream API instead of local TUF client. in github.com/sigstore/gitsign
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/sigstore/gitsign
Introduced in:
0.6.0Fixed in: 0.8.0Fix
go get github.com/sigstore/gitsign@v0.8.0References
- https://github.com/sigstore/gitsign/security/advisories/GHSA-xvrc-2wvh-49vc[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2023-47122[ADVISORY]
- https://github.com/sigstore/gitsign/commit/cd66ccb03c86a3600955f0c15f6bfeb75f697236[FIX]
- https://github.com/sigstore/gitsign/pull/399[FIX]
- https://docs.sigstore.dev/about/threat-model/#sigstore-threat-model[WEB]