Database/Container, Kubernetes & orchestration

cosign / sigstore: Attacker-controlled registry returns unbounded attestations, DoSing the verifier
CVE-2023-46737Container, Kubernetes & orchestrationcurated
Impact
Attacker-controlled registry returns unbounded attestations, DoSing the verifier
Who can reach it
Malicious registry, e.g. a tenant-specified image source
What to do
Upgrade cosign; restrict which registries the admission controller will contact
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.