CVE-2023-47122
NixOS vulnerability analysis and mitigation

Overview

Gitsign, a software for keyless Git signing using Sigstore, contained a vulnerability in versions 0.6.0 through 0.8.0 where Rekor public keys were fetched via the Rekor API instead of through the local TUF client. This vulnerability was identified as CVE-2023-47122 and was discovered on November 10, 2023. The vulnerability affected the verification process of cryptographic signatures (GitHub Advisory).

Technical details

The vulnerability stems from an improper verification of cryptographic signatures (CWE-347). If the upstream Rekor server was compromised, gitsign clients could potentially be tricked into trusting incorrect signatures. The vulnerability has a CVSS v3.1 base score of 5.3 MEDIUM (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N) according to NVD, while GitHub rates it as 4.2 MEDIUM (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N) (NVD).

Impact

The vulnerability could allow attackers to trick gitsign clients into trusting incorrect signatures if the upstream Rekor server was compromised. However, there is no known compromise of the default public good instance (rekor.sigstore.dev), meaning users of this instance were likely unaffected (GitHub Advisory).

Mitigation and workarounds

The vulnerability was fixed in version 0.8.0 of gitsign. The fix involved changing how Rekor public keys are fetched, making them come through the local TUF client instead of the Rekor API. No known workarounds were available for affected versions (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-12819HIGH8.1
  • NixOSNixOS
  • pgbouncer
NoYesDec 03, 2025
CVE-2025-20777MEDIUM6.7
  • NixOSNixOS
  • android
NoNoDec 02, 2025
CVE-2025-65105MEDIUM5.3
  • NixOSNixOS
  • apptainer
NoYesDec 02, 2025
CVE-2025-20789MEDIUM4.4
  • NixOSNixOS
  • android
NoNoDec 02, 2025
CVE-2025-20788MEDIUM4.4
  • NixOSNixOS
  • android
NoNoDec 02, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management