CVE-2021-41087

MEDIUM

in-toto-golang - Privilege Escalation

Title source: llm
STIX 2.1

Description

in-toto-golang is a go implementation of the in-toto framework to protect software supply chain integrity. In affected versions authenticated attackers posing as functionaries (i.e., within a trusted set of users for a layout) are able to create attestations that may bypass DISALLOW rules in the same layout. An attacker with access to trusted private keys, may issue an attestation that contains a disallowed artifact by including path traversal semantics (e.g., foo vs dir/../foo). Exploiting this vulnerability is dependent on the specific policy applied. The problem has been fixed in version 0.3.0.

References (2)

Core 2

Scores

CVSS v3 5.6
EPSS 0.0042
EPSS Percentile 33.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N

Details

CWE
CWE-22 CWE-345
Status published
Products (2)
in-toto/in-toto-golang < 0.3.0
in-toto/in-toto-golang 0 - 0.3.0Go
Published Sep 21, 2021
Tracked Since Feb 18, 2026