Docker Notary Signature Algorithm Not Matched to Key vulnerability
High severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Aug 2, 2023
Description
Published by the National Vulnerability Database
Mar 31, 2018
Published to the GitHub Advisory Database
May 14, 2022
Last updated
Aug 2, 2023
Reviewed
Aug 2, 2023
In Docker Notary before 0.1, gotuf/signed/verify.go has a Signature Algorithm Not Matched to Key vulnerability. Because an attacker controls the field specifying the signature algorithm, they might (for example) be able to forge a signature by forcing a misinterpretation of an RSA-PSS key as Ed25519 elliptic-curve data.
References