CyberRota Analysis
AI-GeneratedA vulnerability in the `openshift/oc-mirror` tool allows for improper verification of PGP signatures, enabling remote attackers to bypass signature checks and inject malicious payloads into disconnected registries. This flaw compromises the integrity of software deployments by allowing crafted PGP messages with valid Red Hat release key IDs but forged signatures. Organizations using `oc-mirror` for managing software images should prioritize addressing this vulnerability to safeguard their deployment environments.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature verification. A remote attacker, by intercepting or manipulating network traffic to the signature endpoint, could exploit this to craft a PGP message with a valid Red Hat release key ID but a forged signature. This enables the `oc-mirror` tool to accept and mirror a malicious release payload into a disconnected registry, potentially compromising the integrity of software deployments.