VDB

CVE-2022-0317

CVE-2022-0317 PUBLISHED CVSS 4 MEDIUM

An improper input validation vulnerability in go-attestation before 0.3.3 allows local users to provide a maliciously-formed Quote over no/some PCRs, causing AKPublic.Verify to succeed despite the inconsistency. Subsequent use of the same set of PCR values in Eventlog.Verify lacks the authentication performed by quote verification, meaning a local attacker could couple this vulnerability with a maliciously-crafted TCG log in Eventlog.Verify to spoof events in the TCG log, hence defeating remotely-attested measured-boot. We recommend upgrading to Version 0.4.0 or above.

EPSS 0.10% · 0.8th percentile

Risk Scores

CVSS 3.1
4
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS Score
0.10%
0.8th percentile

Affected Products

VendorProductVersions
github.comgoogle/go-attestation0
Google LLCgo-attestation*
googlego-attestation0

Timeline

  • Feb 1, 2022 CVE Published
  • Feb 8, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 24, 2022 EPSS Score
  • Jul 16, 2022 EPSS Score
  • Sep 7, 2022 EPSS Score
  • Oct 29, 2022 EPSS Score
  • Dec 21, 2022 EPSS Score
  • Feb 9, 2023 CVE Updated
  • Feb 11, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 5, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›