cosign verify-attestation
used with the --type
flag will report a false positive verification when:
This can happen when signing with a standard keypair and with "keyless" signing with Fulcio. Users should upgrade to cosign version 1.10.1 or greater for a patch. Currently the only workaround is to upgrade.
{ "severity": "HIGH", "github_reviewed_at": "2022-08-10T18:40:38Z", "cwe_ids": [ "CWE-347" ], "nvd_published_at": "2022-08-04T19:15:00Z", "github_reviewed": true }