Improper Verification of Cryptographic Signature
CVE-2024-53267
Summary
The sigstore-java is a sigstore java client for interacting with sigstore infrastructure. The sigstore-java has insufficient verification for a situation where a validly-signed but "mismatched" bundle is presented as proof of inclusion into a transparency log. This bug impacts clients using any variation of "KeylessVerifier.verify()." The verifier may accept a bundle with an unrelated log entry, cryptographically verifying everything, but fails to ensure the log entry applies to the artifact in question, thereby "verifying" a bundle without any proof the signing event was logged. This allows the creation of a bundle without a Fulcio certificate and private key combined with an unrelated but time-correct log entry to fake logging of a signing event. A malicious actor using a compromised identity may want to do this to prevent discovery via Rekor's log monitors. The signer's identity will still be available to the verifier. The signature on the bundle must still be on the correct artifact for the verifier to pass. The "sigstore-gradle-plugin" and "sigstore-maven-plugin" are not affected by this as they only provide signing functionality. This issue affects dev.sigstore:sigstore-java versions prior to 1.1.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.
- LOW
- LOCAL
- HIGH
- UNCHANGED
- NONE
- LOW
- NONE
- NONE
CWE-347 - Improper Verification of Cryptographic Signature
A cryptographic protocol is meant to ensure that services are provided in a secure manner. An application with absent or improper verification of cryptographic signatures allows malicious users to feed false messages to valid users or to disclose sensitive data, subverting the goals of the protocol. This can lead to security failures such as false authentication, account hijacking, and privilege escalation.
References
Advisory Timeline
- Published