A flaw was found in osbuild-composer. A condition can be...
Moderate severity
Unreviewed
Published
Mar 19, 2024
to the GitHub Advisory Database
•
Updated May 22, 2024
Description
Published by the National Vulnerability Database
Mar 19, 2024
Published to the GitHub Advisory Database
Mar 19, 2024
Last updated
May 22, 2024
A flaw was found in osbuild-composer. A condition can be triggered that disables GPG verification for package repositories, which can expose the build phase to a Man-in-the-Middle attack, allowing untrusted code to be installed into an image being built.
References