PT-2022-23036 · Unknown · Policycontroller

Mattmoor

·

Published

2022-08-04

·

Updated

2024-08-21

·

CVE-2022-35930

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PolicyController versions prior to 0.2.1
Description The issue arises when there is at least one attestation with a valid signature and no attestations of the type being verified, with --type defaulting to "custom". This results in a false positive, leading to an admission when it should not be admitted. An example image to test this is ghcr.io/distroless/static@sha256:dd7614b5a12bc4d617b223c588b4e0c833402b8f4991fb5702ea83afad1986e2.
Recommendations To resolve this issue, users should upgrade to version 0.2.1 or greater. There are no workarounds for users unable to upgrade.

Exploit

Fix

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

CVE-2022-35930
GHSA-739F-HW6H-7WQ8
GO-2022-0759

Affected Products

Policycontroller