CVE-2023-47122
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/11/2023
Last modified:
16/11/2023
Description
Gitsign is software for keyless Git signing using Sigstore. In versions of gitsign starting with 0.6.0 and prior to 0.8.0, Rekor public keys were fetched via the Rekor API, instead of through the local TUF client. If the upstream Rekor server happened to be compromised, gitsign clients could potentially be tricked into trusting incorrect signatures. There is no known compromise the default public good instance (`rekor.sigstore.dev`) - anyone using this instance is unaffected. This issue was fixed in v0.8.0. No known workarounds are available.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sigstore:gitsign:*:*:*:*:*:go:*:* | 0.6.0 (including) | 0.8.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



