DirectorySecurity Advisories
Sign In
Security Advisories

CGA-x6rm-c53h-p7jw

Published

Last updated

https://images.chainguard.dev/security/CGA-x6rm-c53h-p7jw
Package

flux-fips-2.4

Latest Update
Fixed
Fixed Version

2.4.0-r4

Aliases
  • CVE-2024-56138
  • GHSA-45v3-38pc-874v

Severity

4.0

Medium

CVSS V3

Summary

notation-go's timestamp signature generation lacks certificate revocation check

Description

This issue was identified during Quarkslab's audit of the timestamp feature.

Summary

During the timestamp signature generation, the revocation status of the certificate(s) used to generate the timestamp signature was not verified.

Details

During timestamp signature generation, notation-go did not check the revocation status of the certificate chain used by the TSA. This oversight creates a vulnerability that could be exploited through a Man-in-The-Middle attack. An attacker could potentially use a compromised, intermediate, or revoked leaf certificate to generate a malicious countersignature, which would then be accepted and stored by notation.

Impact

This could lead to denial of service scenarios, particularly in CI/CD environments during signature verification processes because timestamp signature would fail due to the presence of a revoked certificate(s) potentially disrupting operations.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images