sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker holding expired key material to sign accepted bundles. This issue is fixed in version 1.2.1.
The product uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Hardened Images | RedHat | spire1-15-main-1.15.2-0.3.hum1 | * |
| Red Hat Hardened Images | RedHat | spire1-14-main-1.14.7-0.3.hum1 | * |
| Red Hat Hardened Images | RedHat | trivy-main-0.72.0-0.1.3.hum1 | * |
| Sigstore-go | Ubuntu | upstream | * |