{"id":"BIT-cosign-2022-35929","summary":"False positive signature verification in cosign","details":"cosign is a container signing and verification utility. In versions prior to 1.10.1 cosign can report a false positive if any attestation exists. `cosign verify-attestation` used with the `--type` flag will report a false positive verification when there is at least one attestation with a valid signature and there are NO attestations of the type being verified (--type defaults to \"custom\"). This can happen when signing with a standard keypair and with \"keyless\" signing with Fulcio. This vulnerability can be reproduced with the `distroless.dev/static@sha256:dd7614b5a12bc4d617b223c588b4e0c833402b8f4991fb5702ea83afad1986e2` image. This image has a `vuln` attestation but not an `spdx` attestation. However, if you run `cosign verify-attestation --type=spdx` on this image, it incorrectly succeeds. This issue has been addressed in version 1.10.1 of cosign. Users are advised to upgrade. There are no known workarounds for this issue.","aliases":["CVE-2022-35929","GHSA-vjxv-45g9-9296","GO-2022-0758"],"modified":"2026-09-08T08:45:29.103236988Z","published":"2024-03-06T10:51:23.199Z","database_specific":{"severity":"Critical","cpes":["cpe:2.3:a:sigstore:cosign:*:*:*:*:*:*:*:*"]},"references":[{"type":"ADVISORY","url":"https://github.com/sigstore/cosign/commit/c5fda01a8ff33ca981f45a9f13e7fb6bd2080b94"},{"type":"ADVISORY","url":"https://github.com/sigstore/cosign/security/advisories/GHSA-vjxv-45g9-9296"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-35929"}],"affected":[{"package":{"name":"cosign","ecosystem":"Bitnami","purl":"pkg:bitnami/cosign"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.10.1"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/cosign/BIT-cosign-2022-35929.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}],"schema_version":"1.9.0"}