Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Esposem

#30132de 53,632
8.7CVSS total
Vulnerabilidades · 1
PT-2025-41491
8.7
2025-10-09
Unknown · Confidential Containers Trustee · CVE-2025-61779
**Name of the Vulnerable Software and Affected Versions** Confidential Containers Trustee versions prior to 0.15.0 **Description** The Confidential Containers Trustee project, which includes tools for attesting confidential guests and providing secrets, had a flaw in the attestation-policy endpoint. Before version 0.15.0, the endpoint did not verify the authentication of the `kbs-client` making the request, allowing any client to modify the attestation policy. The `kbs-client` could submit requests to the `/attestation-policy` API endpoint without proper authentication. **Recommendations** Update to version 0.15.0 or later.