GO-2022-0294

    Dashboard / Vulnerabilities / GO-2022-0294

    GO-2022-0294

    Published: 15 Jul 2022Last Modified: 20 May 2024

    Summary: Improper input validation in github.com/google/go-attestation

    Details: A local attacker can defeat remotely-attested measured boot. Improper input validation in AKPublic.Verify can cause it to succeed when provided with a maliciously-formed Quote over no/some PCRs. Subsequent use of the same set of PCR values in Eventlog.Verify lacks the authentication performed by quote verification, meaning a local attacker can couple this vulnerability with a maliciously-formed TCG log in Eventlog.Verify to spoof events in the TCG log, defeating remotely-attested measured-boot.

    Affected packages

    Package

    Name: github.com/google/go-attestation

    Purl: pkg:golang/github.com/google/go-attestation

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.4.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GO-2022-0294 | CVE-DB