CVE-2024-29902

CVSS 3.1 Score 4.2 of 10 (medium)

Details

Published Apr 10, 2024
Updated: Apr 11, 2024
CWE ID 770

Summary

CVE-2024-29902 is a vulnerability affecting Cosign, a code signing and transparency tool for containers and binaries. Before version 2.2.4, Cosign was susceptible to a denial-of-service (DoS) attack via a remote image with a maliciously large attachment. The attachment was read entirely into memory by Cosign without checking its size, potentially causing the host machine to run out of memory and crash. Consequences of this vulnerability include data loss for reliant services like Redis databases and unavailability of other services. Attackers could exploit this vulnerability by compromising a registry or image vendor's account to distribute malicious images. The DoS attack could also allow for supply-chain escalation, harming the image consumer. Cosign has addressed this issue with a patch in version 2.2.4.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share