QID 980518
QID 980518: Go (go) Security Update for github.com/in-toto/in-toto-golang (GHSA-vrxp-mg9f-hwf3)
Security update has been released for github.com/in-toto/in-toto-golang to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Authenticated attackers posing as functionaries (i.e., within a trusted set of users for a layout) are able to create attestations that may bypass DISALLOW rules in the same layout. An attacker with access to trusted private keys, may issue an attestation that contains a disallowed artifact by including path traversal semantics (e.g., foo vs dir/../foo).
Solution
The problem has been fixed in version 0.3.0.Workaround:
Exploiting this vulnerability is dependent on the specific policy applied.
Exploiting this vulnerability is dependent on the specific policy applied.
Vendor References
- GHSA-vrxp-mg9f-hwf3 -
github.com/advisories/GHSA-vrxp-mg9f-hwf3
CVEs related to QID 980518
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vrxp-mg9f-hwf3 | github.com/in-toto/in-toto-golang |
|