The vendor explicitly identifies these products as affected by this CVE.
- openshift-sandboxed-containers/osc-podvm-payload-rhel9 as a component of Confidential Compute Attestation
- clevis-pin-trustee.src as a component of Red Hat Enterprise Linux 10
- trustee-kbs as a component of Red Hat Enterprise Linux 10
- clevis-pin-trustee.src as a component of Red Hat Enterprise Linux 9
- kata-containers as a component of Red Hat OpenShift Container Platform 4
- kata-containers.src as a component of Red Hat OpenShift Container Platform 4
- rhtpa/rhtpa-trustification-service-rhel9 as a component of Red Hat Trusted Profile Analyzer
- Summary
- A flaw was found in AWS-LC. An unauthenticated user can bypass signature verification when processing PKCS7 objects with Authenticated Attributes due to improper signature validation in the PKCS7_verify() function. This vulnerability allows an attacker to potentially compromise the integrity of signed data.
- Remediation
- Red Hat Trusted Artifact Signer simplifies cryptographic signing and verifying of software artifacts such as container images, binaries and source code changes. It is a self-managed on-premise deployment of the Sigstore project available at https://sigstore.dev Platform Engineers, Software Developers and Security Professionals may use RHTAS to ensure the integrity, transparency and assurance of their organization's software supply chain. For details on using the operator, refer to the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3 You can find the release notes for this version of Red Hat Trusted Artifact Signer at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3/html-single/release_notes/index
