Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1tNW0zLTQ2Z2otd2NoOM4AAvLn

SIF's Digital Signature Hash Algorithms Not Validated

Impact

The github.com/sylabs/sif/v2/pkg/integrity package does not verify that the hash algorithm(s) used are cryptographically secure when verifying digital signatures.

Patches

A patch is available in version >= v2.8.1 of the module. Users are encouraged to upgrade.

The patch is commit https://github.com/sylabs/sif/commit/07fb86029a12e3210f6131e065570124605daeaa

Workarounds

Users may independently validate that the hash algorithm(s) used for metadata digest(s) and signature hash are cryptographically secure.

References

For more information

If you have any questions or comments about this advisory:

Permalink: https://github.com/advisories/GHSA-m5m3-46gj-wch8
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tNW0zLTQ2Z2otd2NoOM4AAvLn
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 1 year ago
Updated: about 1 year ago


CVSS Score: 6.3
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

Identifiers: GHSA-m5m3-46gj-wch8, CVE-2022-39237
References: Repository: https://github.com/sylabs/sif
Blast Radius: 16.7

Affected Packages

go:github.com/sylabs/sif/v2
Dependent packages: 281
Dependent repositories: 455
Downloads:
Affected Version Ranges: < 2.8.1
Fixed in: 2.8.1
All affected versions: 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.2.3, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.4.2, 2.5.0, 2.6.0, 2.7.0, 2.7.1, 2.7.2, 2.8.0
All unaffected versions: 2.8.1, 2.8.2, 2.8.3, 2.9.0, 2.9.1, 2.9.2, 2.10.0, 2.11.0, 2.11.1, 2.11.2, 2.11.3, 2.11.4, 2.11.5, 2.12.0, 2.13.0, 2.14.0, 2.14.1, 2.15.0, 2.15.1