QID 995930
Date Published: 2023-11-16
QID 995930: GO (Go) Security Update for github.com/sigstore/gitsign (GHSA-xvrc-2wvh-49vc)
In certain versions of gitsign, Rekor public keys were fetched via the Rekor API, instead of through the local TUF client. If the upstream Rekor server happened to be compromised, gitsign clients could potentially be tricked into trusting incorrect signatures.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-xvrc-2wvh-49vc for updates and patch information.
Vendor References
- GHSA-xvrc-2wvh-49vc -
github.com/advisories/GHSA-xvrc-2wvh-49vc
CVEs related to QID 995930
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xvrc-2wvh-49vc | github.com/sigstore/gitsign |
|