
We found results for “”
WS-2023-0140
Date: August 19, 2025
In the package in-toto up to 1.4.0, the PGP trust model is not (fully) considered: PGP Key Creation Time Not Validated, and PGP Key Usage Flags and PGP Key Revocation are not considered. The preferred mitigation strategy is to verify these properties when exporting a public key from GnuPG, and to clarify usage documentation that no verification against the PGP trust model is performed afterwards. This mitigation addresses all 3 issues of this vulnerability.
Language: Python
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Improper Certificate Validation
CWE-295CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | LOW |
Integrity (I): | LOW |
Availability (A): | LOW |