CVE-2025-61779

Source
https://cve.org/CVERecord?id=CVE-2025-61779
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-61779.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-61779
Aliases
  • GHSA-49mc-2q77-m99x
Published
2025-10-09T20:53:33.855Z
Modified
2026-08-12T03:51:44.231988653Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Trustee's attestation-policy endpoint is not protected by admin autentication
Details

Confidential Containers's Trustee project contains tools and components for attesting confidential guests and providing secrets to them. In versions prior to 0.15.0, the attestation-policy endpoint didn't check if the kbs-client submitting the request was actually authenticated (had the right key). This allowed any kbs-client to actually change the attestation policy. Version 0.15.0 fixes the issue.

Database specific
{
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/61xxx/CVE-2025-61779.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/confidential-containers/trustee

Affected ranges

Type
GIT
Repo
https://github.com/confidential-containers/trustee
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.15.0"
        }
    ]
}

Affected versions

v0.*
v0.10.0
v0.10.1
v0.11.0
v0.12.0
v0.13.0
v0.14.0
v0.5.0
v0.6.0
v0.7.0
v0.8.0
v0.8.2
v0.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-61779.json"