CVE Feed

    Dashboard / CVE / CVE-2024-29903

    CVE-2024-29903

    Cosign provides code signing and transparency for containers and binaries. Prior to version 2.2.4, maliciously-crafted software artifacts can cause denial of service of the machine running Cosign thereby impacting all services on the machine. The root cause is that Cosign creates slices based on the number of signatures, manifests or attestations in untrusted artifacts. As such, the untrusted artifact can control the amount of memory that Cosign allocates. The exact issue is Cosign allocates excessive memory on the lines that creates a slice of the same length as the manifests. Version 2.2.4 contains a patch for the vulnerability.

    Published:Apr 10, 2024
    Last Modified:Jan 9, 2025
    EPS:Apr 10, 2024
    EPSS Score:0.00381
    CVSS Score:4.2

    Affected Products

    Vendor
    Redhat
    Product
    Advanced Cluster Security
    Vendor
    Sigstore
    Product
    Cosign

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High