VDB
CVE-2022-0317
CVE-2022-0317
PUBLISHED
CVSS 4 MEDIUM
An improper input validation vulnerability in go-attestation before 0.3.3 allows local users to provide a maliciously-formed Quote over no/some PCRs, causing AKPublic.Verify to succeed despite the inconsistency. Subsequent use of the same set of PCR values in Eventlog.Verify lacks the authentication performed by quote verification, meaning a local attacker could couple this vulnerability with a maliciously-crafted TCG log in Eventlog.Verify to spoof events in the TCG log, hence defeating remotely-attested measured-boot. We recommend upgrading to Version 0.4.0 or above.
EPSS 0.10% · 0.8th percentile
Risk Scores
CVSS 3.1
4
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS Score
0.10%
0.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | google/go-attestation | 0 |
| Google LLC | go-attestation | * |
| go-attestation | 0 |
Timeline
- Feb 1, 2022 CVE Published
- Feb 8, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 24, 2022 EPSS Score
- Jul 16, 2022 EPSS Score
- Sep 7, 2022 EPSS Score
- Oct 29, 2022 EPSS Score
- Dec 21, 2022 EPSS Score
- Feb 9, 2023 CVE Updated
- Feb 11, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 5, 2023 EPSS Score
References
- https://github.com/google/go-attestation/security/advisories/GHSA-99cg-575x-774p url
- https://nvd.nist.gov/vuln/detail/CVE-2022-0317 advisory
- https://github.com/google/go-attestation/commit/82f2c9c2c76e1d3691d17ee78116d1d93a123788 url
- https://github.com/google/go-attestation url
- https://pkg.go.dev/vuln/GO-2022-0294 url