MEDIUM 5.3 Go

malformed proposed intoto entries can cause a panic

GHSA-frqx-jfcm-6jjr · CVE-2023-33199 · GO-2023-1795

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

A malformed proposed entry of the intoto/v0.0.2 type can cause a panic on a thread within the Rekor process. The thread is recovered so the client receives a 500 error message and service still continues, so the availability impact of this is minimal.

Patches

This is fixed in v1.2.0 of Rekor.

Workarounds

No

References

Discovered by OSS-Fuzz

Ready to move

Start Securing

Free, no credit card | First findings in minutes