Insufficient data authenticity validation In nodejs-22
Description
A flaw was found in sigstore. The certificateOIDs option, intended to restrict which certificates can sign artifacts, is accepted by the public application programming interface (API) but is not used during the verification process. This allows unauthorized certificates to be accepted, bypassing security policies that rely on specific certificate extension object identifiers (OIDs). As a result, applications that depend on this option for security receive no protection, potentially leading to the acceptance of malicious or untrusted artifacts.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 4.1.1 | ||
rpm rhel9 | - | - | |
rpm rhel8 | - | - | |
rpm rhel10 | - | - | |
rpm rhel8 | - | - | |
rpm rhel9 | - | - | |
rpm rhel8 | - | - | |
rpm rhel10 | - | - | |
rpm rhel8 | - | - | |
rpm rhel9 | - | - |
1-10 of 11
10
Aliases
References