Credential disclosure in syft when SYFT_ATTEST_PASSWORD environment variable set in syft
CVE-2023-24827
6.5MEDIUM
What is CVE-2023-24827?
A vulnerability in the Syft tool, affecting versions v0.69.0 and v0.69.1, allows for the unintended exposure of the password stored in the SYFT_ATTEST_PASSWORD environment variable. This exposure occurs during the logging process at debug levels and in SBOM attestations generated with the syft-json format, potentially leaking sensitive credentials. The vulnerability affects any users with this environment variable set, leading to the risk of credential theft, particularly when attestations are uploaded to an OCI registry. The issue has been resolved in version v0.70.0, and users are strongly encouraged to upgrade to mitigate this risk.
Affected Version(s)
syft >= 0.69.0, < 0.70.0
