CVE-2023-33199 is a denial-of-service vulnerability affecting Rekor, a software supply chain metadata ledger. A specially crafted "intoto/v0.0.2" entry can trigger a panic in a Rekor process thread, leading to a 500 error for the client, though the service itself remains operational. Rated Medium (CVSS 5.3), this vulnerability requires no user interaction and has low availability impact. There is no known exploit code, active exploitation, or significant community discussion surrounding this CVE. Users are advised to upgrade to Rekor v1.2.0 to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:rekor:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.