Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-41087

Опубликовано: 21 сент. 2021
Источник: nvd
CVSS3: 5.6
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

in-toto-golang is a go implementation of the in-toto framework to protect software supply chain integrity. In affected versions authenticated attackers posing as functionaries (i.e., within a trusted set of users for a layout) are able to create attestations that may bypass DISALLOW rules in the same layout. An attacker with access to trusted private keys, may issue an attestation that contains a disallowed artifact by including path traversal semantics (e.g., foo vs dir/../foo). Exploiting this vulnerability is dependent on the specific policy applied. The problem has been fixed in version 0.3.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:in-toto:in-toto-golang:*:*:*:*:*:*:*:*
Версия до 0.3.0 (исключая)

EPSS

Процентиль: 38%
0.00168
Низкий

5.6 Medium

CVSS3

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-345
CWE-22

Связанные уязвимости

CVSS3: 5.6
github
больше 4 лет назад

Improperly Implemented path matching for in-toto-golang

EPSS

Процентиль: 38%
0.00168
Низкий

5.6 Medium

CVSS3

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-345
CWE-22