Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-48816

Опубликовано: 01 июл. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.1.1, @sigstore/verify derives a transparency-log timestamp from tlogEntries[].integratedTime for bundle v0.2 inclusionProof-only entries even though the inclusion proof path does not cryptographically bind integratedTime, allowing an attacker who can supply an untrusted bundle to influence certificate validity and timestampThreshold verification decisions. This issue is fixed in version 3.1.1.

A flaw was found in sigstore-js. The software derives a transparency-log timestamp from tlogEntries[].integratedTime and uses it to validate certificate validity windows and satisfy timestampThreshold. For bundle v0.2, a transparency log (tlog) entry can be inclusion-proof-only, meaning the inclusion proof path does not cryptographically bind the integratedTime. This allows an attacker who can supply an untrusted bundle to influence time-based verification decisions by choosing an arbitrary integratedTime. This could lead to incorrect validation of certificate validity.

Отчет

A flaw was found in sigstore-js. The tlog integratedTime field is not cryptographically bound in inclusionProof-only bundle v0.2 entries, allowing an attacker who supplies an untrusted bundle to influence time-based verification decisions.

Меры по смягчению последствий

Upgrade to the latest sigstore-js (>= 3.1.1) release that addresses GHSA-xgjw-pm74-86q4.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10sigstoreFix deferred
Red Hat Enterprise Linux 8sigstoreFix deferred
Red Hat Enterprise Linux 9sigstoreFix deferred
Red Hat OpenShift Dev SpacessigstoreFix deferred
Red Hat Satellite 6sigstoreFix deferred
Self-service automation portal 2sigstoreFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-345
https://bugzilla.redhat.com/show_bug.cgi?id=2499688sigstore-js: github.com/sigstore/sigstore-js: sigstore-js: Insufficient verification of data authenticity allows timestamp manipulation

EPSS

Процентиль: 5%
0.00158
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
23 дня назад

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.1.1, @sigstore/verify derives a transparency-log timestamp from tlogEntries[].integratedTime for bundle v0.2 inclusionProof-only entries even though the inclusion proof path does not cryptographically bind integratedTime, allowing an attacker who can supply an untrusted bundle to influence certificate validity and timestampThreshold verification decisions. This issue is fixed in version 3.1.1.

CVSS3: 6.5
github
около 1 месяца назад

sigstore-js has Insufficient Verification of Data Authenticity

EPSS

Процентиль: 5%
0.00158
Низкий

6.5 Medium

CVSS3