{"schema_version":"1.7.3","id":"SUSE-SU-2024:0460-1","published":"2024-02-13T14:29:55Z","modified":"2026-02-04T03:12:21.655431Z","related":["CVE-2023-48795"],"upstream":["CVE-2023-48795"],"summary":"Security update for rekor","details":"This update for rekor fixes the following issues:\n\nupdate to 1.3.5 (jsc#SLE-23476):\n\n  - Additional unique index correction\n  - Remove timestamp from checkpoint\n  - Drop conditional when verifying entry checkpoint\n  - Fix panic for DSSE canonicalization\n  - Change Redis value for locking mechanism\n  - give log timestamps nanosecond precision\n  - output trace in slog and override correlation header name\n\n- bumped embedded golang.org/x/crypto/ssh to fix the Terrapin attack CVE-2023-48795 (bsc#1218207)\n\nUpdated to 1.3.4:\n\n  * add mysql indexstorage backend\n  * add s3 storage for attestations\n  * fix: Do not check for pubsub.topics.get on initialization\n  * fix optional field in cose schema\n  * Update ranges.go\n  * update indexstorage interface to reduce roundtrips\n  * use a single validator library in rekor-cli\n  * Remove go-playground/validator dependency from pkg/pki\n\nUpdated to rekor 1.3.3 (jsc#SLE-23476):\n\n  - Update signer flag description\n  - update trillian to 1.5.3\n  - adds redis_auth\n  - Add method to get artifact hash for an entry\n  - make e2e tests more usable with docker-compose\n  - install go at correct version for codeql\n\nUpdated to rekor 1.3.2 (jsc#SLE-23476):\n\n\nUpdated to rekor 1.3.1 (jsc#SLE-23476):\n\nNew Features:\n\n  - enable GCP cloud profiling on rekor-server (#1746)\n  - move index storage into interface (#1741)\n  - add info to readme to denote additional documentation sources (#1722)\n  - Add type of ed25519 key for TUF (#1677)\n  - Allow parsing base64-encoded TUF metadata and root content (#1671)\n\n  Quality Enhancements:\n\n  - disable quota in trillian in test harness (#1680)\n\n  Bug Fixes:\n\n  - Update contact for code of conduct (#1720)\n  - Fix panic when parsing SSH SK pubkeys (#1712)\n  - Correct index creation (#1708)\n  - docs: fixzes a small typo on the readme (#1686)\n  - chore: fix backfill-redis Makefile target (#1685)\n\nUpdated to rekor 1.3.0 (jsc#SLE-23476):\n\n  - Update openapi.yaml (#1655)\n  - pass transient errors through retrieveLogEntry (#1653)\n  - return full entryID on HTTP 409 responses (#1650)\n  - feat: Support publishing new log entries to Pub/Sub topics (#1580)\n  - Change values of Identity.Raw, add fingerprints (#1628)\n  - Extract all subjects from SANs for x509 verifier (#1632)\n  - Fix type comment for Identity struct (#1619)\n  - Refactor Identities API (#1611)\n  - Refactor Verifiers to return multiple keys (#1601)\n  - Update checkpoint link (#1597)\n  - Use correct log index in inclusion proof (#1599)\n  - remove instrumentation library (#1595)\n\nUpdated to rekor 1.2.2 (jsc#SLE-23476):\n\n  - pass down error with message instead of nil\n  - swap killswitch for 'docker-compose restart'\n\n- CVE-2023-48795: Fixed Terrapin attack in embedded golang.org/x/crypto/ssh (bsc#1218207).\n","affected":[{"package":{"name":"rekor","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP5","purl":"pkg:rpm/suse/rekor&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.5-150400.4.19.1"}]}],"ecosystem_specific":{"binaries":[{"rekor":"1.3.5-150400.4.19.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0460-1.json"}},{"package":{"name":"rekor","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/rekor&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.5-150400.4.19.1"}]}],"ecosystem_specific":{"binaries":[{"rekor":"1.3.5-150400.4.19.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0460-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2024/suse-su-20240460-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218207"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-48795"}]}