CVE-2022-23649 is a low-severity vulnerability affecting sigstore Cosign versions prior to 1.5.2, allowing an attacker with push/pull OCI permissions to manipulate Cosign into falsely believing a signature entry exists in the Rekor transparency log. The attack vector is local with low complexity, resulting in a low impact on integrity (CVSS 3.3). There is no known active exploitation, public exploit code, or significant community discussion surrounding this vulnerability. The issue has been patched in Cosign v1.5.2 by verifying the signature in the signedEntryTimestamp against the signature being verified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.2CPE matchmatch criteria | cpe:2.3:a:sigstore:cosign:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.