CVE Vulnerabilities

CVE-2024-2307

Improper Verification of Cryptographic Signature

Published: Mar 19, 2024 | Modified: May 22, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.1 MODERATE
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L
Ubuntu

A flaw was found in osbuild-composer. A condition can be triggered that disables GPG verification for package repositories, which can expose the build phase to a Man-in-the-Middle attack, allowing untrusted code to be installed into an image being built.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Red Hat Enterprise Linux 8 RedHat osbuild-composer-0:101-1.el8 *
Red Hat Enterprise Linux 9 RedHat osbuild-composer-0:101-1.el9 *

References