Executive brief
The go-tuf library, which implements a framework for securing software update systems, contains a flaw in how it validates digital signatures. An attacker who can influence the metadata of a software repository could potentially bypass security thresholds by providing the same cryptographic key multiple times using different identifiers. This could allow a single malicious actor to appear as multiple authorized signers, potentially leading to the distribution of unauthorized or malicious software updates.
Technical details
A vulnerability in go-tuf clients prior to version 0.3.2 allows for an authentication bypass by alternate name (CWE-289). The root cause is the library's failure to deduplicate public keys when they are presented with different Key IDs (e.g., using different hash algorithms like SHA2-256 and SHA2-512 for the same key). If a TUF repository requires a threshold of N signatures, an attacker who controls a valid key can list that same key multiple times in the metadata under different IDs. If they convince other maintainers to sign this metadata, the client will incorrectly count the attacker's single signature multiple times, potentially meeting the required threshold with fewer unique signers than intended. This issue is resolved in version 0.3.2 by ensuring unique public keys are only counted once regardless of the Key ID used.
Affected products
- The Update Framework (TUF) go-tuf < 0.3.2
Timeline
- 2022-09-08: disclosed: Advisory published by the maintainers.
- 2022-09-16: advisory: GitHub Advisory GHSA-3633-5h82-39pq published.
- 2022-09-08: patched: Version 0.3.2 released with fix.
References
- https://api.github.com/users/cedricvanrompay-datadog
- https://github.com/cedricvanrompay-datadog
- https://api.github.com/users/cedricvanrompay-datadog/gists%7B/gist_id%7D
- https://api.github.com/users/cedricvanrompay-datadog/repos
- https://avatars.githubusercontent.com/u/97546950?v=4
- https://api.github.com/users/cedricvanrompay-datadog/events%7B/privacy%7D