CVE-2023-32076 is a medium-severity vulnerability affecting in-toto versions 1.4.0 and prior, where an attacker can manipulate supply chain integrity by providing a malicious .in_totorc file. This local attack, requiring low privileges and no user interaction, could lead to high integrity impacts by masking attacker activities. While no active exploitation, public exploits, or significant community discussion have been observed, the vulnerability has been addressed by removing support for .in_totorc files.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.4.0CPE matchmatch criteria | cpe:2.3:a:in-toto_project:in-toto:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.