cosign verify-attestation used with the --type flag will report a false positive verification when:
This can happen when signing with a standard keypair and with "keyless" signing with Fulcio. Users should upgrade to cosign version 1.10.1 or greater for a patch. Currently the only workaround is to upgrade.
{
"severity": "HIGH",
"github_reviewed_at": "2022-08-10T18:40:38Z",
"cwe_ids": [
"CWE-347"
],
"nvd_published_at": "2022-08-04T19:15:00Z",
"github_reviewed": true
}