SCA: security update for dev.sigstore:sigstore-java (GHSA-q4xm-6fjc-5f6w)

medium Tenable Cloud Security Plugin ID 417885

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has
insufficient verification for a situation where a validly-signed but "mismatched" bundle is presented as
proof of inclusion into a transparency log. This bug impacts clients using any variation of
KeylessVerifier.verify(). The verifier may accept a bundle with an unrelated log entry, cryptographically
verifying everything but fails to ensure the log entry applies to the artifact in question, thereby
"verifying" a bundle without any proof the signing event was logged. This allows the creation of a bundle
without fulcio certificate and private key combined with an unrelated but time-correct log entry to fake
logging of a signing event. A malicious actor using a compromised identity may want to do this to prevent
discovery via rekor's log monitors. The signer's identity will still be available to the verifier. The
signature on the bundle must still be on the correct artifact for the verifier to pass. sigstore-gradle-
plugin and sigstore-maven-plugin are not affected by this as they only provide signing functionality. This
issue has been patched in v1.1.0 release with PR #856. All users are advised to upgrade. There are no
known workarounds for this vulnerability. (CVE-2024-53267)

See Also

https://github.com/advisories/GHSA-q4xm-6fjc-5f6w

Plugin Details

Severity: Medium

ID: 417885

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.92

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:C/A:N

CVSS Score Source: CVE-2024-53267

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 6.8

Threat Score: 4.3

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 11/26/2024

Vulnerability Publication Date: 11/26/2024

Reference Information

CVE: CVE-2024-53267