CVE-2024-29903

CVSS 3.1 Score 4.2 of 10 (medium)

Details

Published Apr 10, 2024
Updated: Apr 11, 2024
CWE ID 770

Summary

CVE-2024-29903 is a Denial of Service vulnerability affecting Cosign, a code signing and transparency tool for containers and binaries. Before version 2.2.4, Cosign is susceptible to maliciously crafted software artifacts that can cause the machine running Cosign to crash, thereby impacting all services on the machine. The root cause of this vulnerability lies in Cosign's creation of slices based on the number of signatures, manifests, or attestations in untrusted artifacts. Malicious artifacts can manipulate this process, causing Cosign to allocate excessive memory. This issue is resolved in version 2.2.4, which includes a patch for the vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share