Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Lasso | Entrouvert | * | 2.7.0 (excluding) |
| Red Hat Enterprise Linux 7 | RedHat | lasso-0:2.5.1-8.el7_9 | * |
| Red Hat Enterprise Linux 8 | RedHat | lasso-0:2.6.0-12.el8 | * |
| Lasso | Ubuntu | bionic | * |
| Lasso | Ubuntu | esm-apps/xenial | * |
| Lasso | Ubuntu | esm-infra/bionic | * |
| Lasso | Ubuntu | esm-infra/focal | * |
| Lasso | Ubuntu | focal | * |
| Lasso | Ubuntu | groovy | * |
| Lasso | Ubuntu | hirsute | * |
| Lasso | Ubuntu | trusty | * |
| Lasso | Ubuntu | xenial | * |