GHSA-vrxp-mg9f-hwf3
Dashboard / Vulnerabilities / GHSA-vrxp-mg9f-hwf3
GHSA-vrxp-mg9f-hwf3
Summary: Improperly Implemented path matching for in-toto-golang
Details: ### Impact Authenticated attackers posing as functionaries (i.e., within a trusted set of users for a layout) are able to create attestations that may bypass DISALLOW rules in the same layout. An attacker with access to trusted private keys, may issue an attestation that contains a disallowed artifact by including path traversal semantics (e.g., foo vs dir/../foo). ### Patches The problem has been fixed in version 0.3.0. ### Workarounds Exploiting this vulnerability is dependent on the specific policy applied. ### For more information If you have any questions or comments about this advisory: * Open an issue in [in-toto-golang](http://github.com/in-toto/in-toto-golang) * Email us at [in-toto-public](mailto:[email protected]) * If this is a sensitive security-relevant disclosure, please send a PGP encrypted email to [email protected] or [email protected]
References: https://github.com/in-toto/in-toto-golang/security/advisories/GHSA-vrxp-mg9f-hwf3, https://nvd.nist.gov/vuln/detail/CVE-2021-41087, https://github.com/in-toto/in-toto-golang/commit/f2c57d1e0f15e3ffbeac531829c696b72ecc4290, https://github.com/in-toto/in-toto-golang
Affected packages
Package
Name: github.com/in-toto/in-toto-golang
Purl: pkg:golang/github.com/in-toto/in-toto-golang
Affected ranges
Type: SEMVER
Events:
