漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
sigstore-ruby verifier returns success for DSSE bundles with mismatched in-toto subject digest
Vulnerability Description
sigstore-ruby is a pure Ruby implementation of the sigstore verify command from the sigstore/cosign project. Prior to 0.2.3, Sigstore::Verifier#verify does not propagate the VerificationFailure returned by verify_in_toto when the artifact digest does not match the digest in the in-toto attestation subject. As a result, verification of DSSE bundles containing in-toto statements returns VerificationSuccess regardless of whether the artifact matches the attested subject. This vulnerability is fixed in 0.2.3.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
未加检查的返回值
Vulnerability Title
Sigstore 安全漏洞
Vulnerability Description
Sigstore是sigstore开源的一个软件签名验证库。 Sigstore 0.2.3之前版本存在安全漏洞,该漏洞源于验证过程中未正确传播验证失败信息,可能导致验证绕过。
CVSS Information
N/A
Vulnerability Type
N/A