Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-72c7-4g63-hpw5

Опубликовано: 15 окт. 2025
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

go-witness is Vulnerable to Improper Verification of AWS EC2 Identity Documents

Impact

This vulnerability only affects users of the AWS attestor.

Users of the AWS attestor could have unknowingly received a forged identity document. While this may seem unlikely, AWS recently issued a security bulletin about IMDS (Instance Metadata Service) impersonation.1

There are multiple locations where the verification of the identity document will mistakenly report a successful verification.

Workarounds

The contents of the AWS attestation contain the identity document, signature, and public key that was used to verify the document. These attestations and their could be identity documents could be manually verified with the openssl command line as documented in the below reference from AWS.2

However, the certificate containing the public key was hard-coded into the attestor. https://github.com/in-toto/go-witness/blob/0c8bb30c143951d88b1d4b32f260c5f67d30137b/attestation/aws-iid/aws-iid.go#L46-L66

Since the original authoring of the attestor, AWS has moved to region specific public certificates. The currently valid certificates were issued around April of 2024, making the identification of attestations with forged content difficult without additional trusted data proving the AWS region in which the attestation was created.

Patches

This vulnerability is addressed in go-witness 0.9.1 and witness 0.10.1.

Resources

Footnotes

  1. AWS Security Bulletin on IMDS Impersonation

  2. Verification of instance identity documents

Пакеты

Наименование

github.com/in-toto/go-witness

go
Затронутые версииВерсия исправления

< 0.9.1

0.9.1

EPSS

Процентиль: 10%
0.00035
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-295

Связанные уязвимости

nvd
4 месяца назад

go-witness and witness are Go modules for generating attestations. In go-witness versions 0.8.6 and earlier and witness versions 0.9.2 and earlier the AWS attestor improperly verifies AWS EC2 instance identity documents. Verification can incorrectly succeed when a signature is not present or is empty, and when RSA signature verification fails. The attestor also embeds a single legacy global AWS public certificate and does not account for newer region specific certificates issued in 2024, making detection of forged documents difficult without additional trusted region data. An attacker able to supply or intercept instance identity document data (such as through Instance Metadata Service impersonation) can cause a forged identity document to be accepted, leading to incorrect trust decisions based on the attestation. This is fixed in go-witness 0.9.1 and witness 0.10.1. As a workaround, manually verify the included identity document, signature, and public key with standard tools (for exam

debian
4 месяца назад

go-witness and witness are Go modules for generating attestations. In ...

EPSS

Процентиль: 10%
0.00035
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-295