SCA: security update for sigstore (GHSA-hhfg-fwrw-87w7)

medium Tenable Self-Hosted Container Security Plugin ID 415763

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- sigstore-python is a Python tool for generating and verifying Sigstore signatures. Versions of sigstore-
python newer than 2.0.0 but prior to 3.6.0 perform insufficient validation of the "integration time"
present in "v2" and "v3" bundles during the verification flow: the "integration time" is verified *if* a
source of signed time (such as an inclusion promise) is present, but is otherwise trusted if no source of
signed time is present. This does not affect "v1" bundles, as the "v1" bundle format always requires an
inclusion promise. Sigstore uses signed time to support verification of signatures made against short-
lived signing keys. The impact and severity of this weakness is *low*, as Sigstore contains multiple other
enforcing components that prevent an attacker who modifies the integration timestamp within a bundle from
impersonating a valid signature. In particular, an attacker who modifies the integration timestamp can
induce a Denial of Service, but in no different manner than already possible with bundle access (e.g.
modifying the signature itself such that it fails to verify). Separately, an attacker could upload a *new*
entry to the transparency service, and substitute their new entry's time. However, this would still be
rejected at validation time, as the new entry's (valid) signed time would be outside the validity window
of the original signing certificate and would nonetheless render the attacker auditable. (CVE-2024-55655)

See Also

https://github.com/advisories/GHSA-hhfg-fwrw-87w7

Plugin Details

Severity: Medium

ID: 415763

Version: Revision 1.9

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.92

Vendor

Vendor Severity: Low

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2024-55655

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Threat Score: 2.7

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 12/11/2024

Vulnerability Publication Date: 12/10/2024

Reference Information

CVE: CVE-2024-55655