Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hm8f-75xx-w2vr

Опубликовано: 26 янв. 2026
Источник: github
Github: Прошло ревью
CVSS3: 0

Описание

sigstore CSRF possibility in OIDC authentication during signing

Summary

The sigstore-python OAuth authentication flow is susceptible to Cross-Site Request Forgery.

Details

_OAuthSession creates a unique "state" and sends it as a parameter in the authentication request but the "state" in the server response seems not not be cross-checked with this value.

Fix should be fairly trivial.

Impact

This should be low impact: A man-in-the middle attacker could trick a sigstore-python user into signing something with an identity controlled by the attacker (by returning the response to an authentication request they created). This would be quite confusing but not dangerous.

Пакеты

Наименование

sigstore

pip
Затронутые версииВерсия исправления

< 4.2.0

4.2.0

EPSS

Процентиль: 0%
0.00007
Низкий

0 Low

CVSS3

Дефекты

CWE-352

Связанные уязвимости

nvd
12 дней назад

sigstore-python is a Python tool for generating and verifying Sigstore signatures. Prior to version 4.2.0, the sigstore-python OAuth authentication flow is susceptible to Cross-Site Request Forgery. `_OAuthSession` creates a unique "state" and sends it as a parameter in the authentication request but the "state" in the server response seems not not be cross-checked with this value. Version 4.2.0 contains a patch for the issue.

debian
12 дней назад

sigstore-python is a Python tool for generating and verifying Sigstore ...

EPSS

Процентиль: 0%
0.00007
Низкий

0 Low

CVSS3

Дефекты

CWE-352