PolicyController will report a false positive, resulting in an admission when it should not be admitted when: * There is at least one attestation with a valid signature * There are NO attestations of the type being verified (--type defaults to "custom")
Users should upgrade to cosign version 0.2.1 or greater for a patch. There are no known workarounds at this time.
{ "nvd_published_at": "2022-08-04T22:15:00Z", "github_reviewed_at": "2022-08-10T18:38:16Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-347" ] }