CVE-2022-35929
Last modified
CVE-2022-35929 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. cosign is a container signing and verification utility. In versions prior to 1.10.1 cosign can report a false positive if any attestation exists. EPSS estimates a 0.54% chance of exploitation in the next 30 days.
Description
cosign is a container signing and verification utility. In versions prior to 1.10.1 cosign can report a false positive if any attestation exists. `cosign verify-attestation` used with the `--type` flag will report a false positive verification when there is at least one attestation with a valid signature and there are NO attestations of the type being verified (--type defaults to "custom"). This can happen when signing with a standard keypair and with "keyless" signing with Fulcio. This vulnerability can be reproduced with the `distroless.dev/static@sha256:dd7614b5a12bc4d617b223c588b4e0c833402b8f4991fb5702ea83afad1986e2` image. This image has a `vuln` attestation but not an `spdx` attestation. However, if you run `cosign verify-attestation --type=spdx` on this image, it incorrectly succeeds. This issue has been addressed in version 1.10.1 of cosign. Users are advised to upgrade. There are no known workarounds for this issue.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sigstore | Cosign | < 1.10.1 |
References
- https://github.com/sigstore/cosign/commit/c5fda01a8ff33ca981f45a9f13e7fb6bd2080b94Exploit, Patch, Third Party Advisory
- https://github.com/sigstore/cosign/security/advisories/GHSA-vjxv-45g9-9296Exploit, Third Party Advisory
- https://github.com/sigstore/cosign/commit/c5fda01a8ff33ca981f45a9f13e7fb6bd2080b94Exploit, Patch, Third Party Advisory
- https://github.com/sigstore/cosign/security/advisories/GHSA-vjxv-45g9-9296Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-35929?
How severe is CVE-2022-35929?
How do I fix CVE-2022-35929?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-35923v8n is a javascript validation library. Versions of v8n prio…7.5
- CVE-2022-35924NextAuth.js is a complete open source authentication solutio…9.1
- CVE-2022-35925BookWyrm is a social network for tracking reading. Versions …9.8
- CVE-2022-35926Contiki-NG is an open-source, cross-platform operating syste…7.5
- CVE-2022-35927Contiki-NG is an open-source, cross-platform operating syste…9.8
- CVE-2022-35928AES Crypt is a file encryption software for multiple platfor…5.5
- CVE-2022-3593Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-35930PolicyController is a utility used to enforce supply chain p…8.8
- CVE-2022-35931Nextcloud Password Policy is an app that enables a Nextcloud…2.7
- CVE-2022-35932Nextcloud Talk is a video and audio conferencing app for Nex…5.3
- CVE-2022-35933This package is a PrestaShop module that allows users to pos…6.1
- CVE-2022-35934TensorFlow is an open source platform for machine learning. …7.5
Are you affected by CVE-2022-35929?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
