VDB
CVE-2021-41087
CVE-2021-41087
PUBLISHED
CVSS 5.599999904632568 MEDIUM
in-toto-golang is a go implementation of the in-toto framework to protect software supply chain integrity. In affected versions authenticated attackers posing as functionaries (i.e., within a trusted set of users for a layout) are able to create attestations that may bypass DISALLOW rules in the same layout. An attacker with access to trusted private keys, may issue an attestation that contains a disallowed artifact by including path traversal semantics (e.g., foo vs dir/../foo). Exploiting this vulnerability is dependent on the specific policy applied. The problem has been fixed in version 0.3.0.
EPSS 0.43% · 36.8th percentile
Risk Scores
CVSS 3.1
5.599999904632568
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N
EPSS Score
0.43%
36.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | in-toto/in-toto-golang | 0 |
| in-toto | in-toto-golang | < 0.3.0, 0 |
Timeline
- Sep 21, 2021 CVE Published
- Sep 22, 2021 EPSS Score
- Oct 5, 2021 CVE Updated
- Nov 19, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Jan 15, 2022 EPSS Score
- Mar 14, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 10, 2022 EPSS Score
- Jul 7, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 31, 2022 EPSS Score