{"schema_version":"1.7.3","id":"SUSE-SU-2024:0430-1","published":"2024-02-08T14:03:31Z","modified":"2026-02-04T03:33:27.370980Z","related":["CVE-2023-48795"],"upstream":["CVE-2023-48795"],"summary":"Security update for cosign","details":"This update for cosign fixes the following issues:\n\nUpdated to 2.2.3 (jsc#SLE-23879):\n\nBug Fixes:\n\n* Fix race condition on verification with multiple signatures attached to image (#3486)\n* fix(clean): Fix clean cmd for private registries (#3446)\n* Fixed BYO PKI verification (#3427)\n\nFeatures:\n\n* Allow for option in cosign attest and attest-blob to upload attestation as supported in Rekor (#3466)\n* Add support for OpenVEX predicate type (#3405)\n\nDocumentation:\n\n* Resolves #3088: `version` sub-command expected behaviour documentation and testing (#3447)\n* add examples for cosign attach signature cmd (#3468)\n\nMisc:\n\n* Remove CertSubject function (#3467)\n* Use local rekor and fulcio instances in e2e tests (#3478)\n\n- bumped embedded golang.org/x/crypto/ssh to fix the Terrapin attack CVE-2023-48795 (bsc#1218207)\n\nUpdated to 2.2.2 (jsc#SLE-23879):\n\nv2.2.2 adds a new container with a shell,\ngcr.io/projectsigstore/cosign:vx.y.z-dev, in addition to the existing\ncontainer gcr.io/projectsigstore/cosign:vx.y.z without a shell.\n\nFor private deployments, we have also added an alias for\n--insecure-skip-log, --private-infrastructure.\n\nBug Fixes:\n\n* chore(deps): bump github.com/sigstore/sigstore from 1.7.5 to 1.7.6 (#3411) which fixes a bug with using Azure KMS\n* Don't require CT log keys if using a key/sk (#3415)\n* Fix copy without any flag set (#3409)\n* Update cosign generate cmd to not include newline (#3393)\n* Fix idempotency error with signing (#3371)\n\nFeatures:\n\n* Add --yes flag cosign import-key-pair to skip the overwrite confirmation. (#3383)\n* Use the timeout flag value in verify* commands. (#3391)\n* add --private-infrastructure flag (#3369)\n\nContainer Updates:\n\n* Bump builder image to use go1.21.4 and add new cosign image tags with shell (#3373)\n\nDocumentation:\n\n* Update SBOM_SPEC.md (#3358)\n\n- CVE-2023-48795: Fixed the Terrapin attack in embedded golang.org/x/crypto/ssh (bsc#1218207).\n","affected":[{"package":{"name":"cosign","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP5","purl":"pkg:rpm/suse/cosign&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.3-150400.3.17.1"}]}],"ecosystem_specific":{"binaries":[{"cosign":"2.2.3-150400.3.17.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0430-1.json"}},{"package":{"name":"cosign","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/cosign&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.3-150400.3.17.1"}]}],"ecosystem_specific":{"binaries":[{"cosign":"2.2.3-150400.3.17.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0430-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2024/suse-su-20240430-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218207"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-48795"}]}