CVE-2024-29903
CVSS 3.1 Score 4.2 of 10 (medium)
Details
Summary
CVE-2024-29903 is a Denial of Service vulnerability affecting Cosign, a code signing and transparency tool for containers and binaries. Before version 2.2.4, Cosign is susceptible to maliciously crafted software artifacts that can cause the machine running Cosign to crash, thereby impacting all services on the machine. The root cause of this vulnerability lies in Cosign's creation of slices based on the number of signatures, manifests, or attestations in untrusted artifacts. Malicious artifacts can manipulate this process, causing Cosign to allocate excessive memory. This issue is resolved in version 2.2.4, which includes a patch for the vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.