CVE-2025-61779

Source
https://cve.org/CVERecord?id=CVE-2025-61779
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-61779.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-61779
Aliases
  • GHSA-49mc-2q77-m99x
Published
2025-10-09T20:53:33.855Z
Modified
2026-04-02T12:57:37.609194Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Trustee's attestation-policy endpoint is not protected by admin autentication
Details

Confidential Containers's Trustee project contains tools and components for attesting confidential guests and providing secrets to them. In versions prior to 0.15.0, the attestation-policy endpoint didn't check if the kbs-client submitting the request was actually authenticated (had the right key). This allowed any kbs-client to actually change the attestation policy. Version 0.15.0 fixes the issue.

Database specific
{
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/61xxx/CVE-2025-61779.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/confidential-containers/trustee

Affected ranges

Type
GIT
Repo
https://github.com/confidential-containers/trustee
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*
v0.10.0
v0.10.1
v0.11.0
v0.12.0
v0.13.0
v0.14.0
v0.5.0
v0.6.0
v0.7.0
v0.8.0
v0.8.2
v0.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-61779.json"