QID 995930

Date Published: 2023-11-16

QID 995930: GO (Go) Security Update for github.com/sigstore/gitsign (GHSA-xvrc-2wvh-49vc)

In certain versions of gitsign, Rekor public keys were fetched via the Rekor API, instead of through the local TUF client. If the upstream Rekor server happened to be compromised, gitsign clients could potentially be tricked into trusting incorrect signatures.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 4.2 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-xvrc-2wvh-49vc for updates and patch information.
    Vendor References

    CVEs related to QID 995930

    Software Advisories
    Advisory ID Software Component Link
    GHSA-xvrc-2wvh-49vc github.com/sigstore/gitsign URL Logo github.com/advisories/GHSA-xvrc-2wvh-49vc