PT-2025-42399 · Witness+1 · Witness+1

Published

2025-10-15

·

Updated

2025-11-07

·

CVE-2025-62375

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions go-witness versions 0.8.6 and earlier witness versions 0.9.2 and earlier
Description The AWS attestor in go-witness and witness improperly verifies AWS EC2 instance identity documents. Verification can incorrectly succeed when a signature is not present or is empty, and when RSA signature verification fails. The attestor embeds a single legacy global AWS public certificate and does not account for newer region-specific certificates issued in 2024, making detection of forged documents difficult without additional trusted region data. An attacker able to supply or intercept instance identity document data can cause a forged identity document to be accepted, leading to incorrect trust decisions based on the attestation.
Recommendations Update go-witness to version 0.9.1 or later. Update witness to version 0.10.1 or later. Manually verify the included identity document, signature, and public key with standard tools following AWS’s verification guidance. Disable use of the AWS attestor until upgraded.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-62375
GHSA-72C7-4G63-HPW5
GO-2025-4028
OPENSUSE-SU-2025:15710-1

Affected Products

Gowitness
Witness