THREAT OPS › Threat News › [GHSA] GHSA-mf7q-r4rv-jv94 (high) — Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check
[GHSA] GHSA-mf7q-r4rv-jv94 (high) — Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check
GHSA-mf7q-r4rv-jv94 Severity: high CVE: None
Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check
## Summary
Crossplane allows package signature verification to be configured via the `ImageConfig` mechanism. When enabled, the package manager uses cosign to verify that packages are correctly signed before
Original source: https://github.com/advisories/GHSA-mf7q-r4rv-jv94