This page aggregates publicly disclosed CVE and security risk information related to cosign, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2007-2233 | cosign-bin/cosign.cgi in Cosign 2.0.2 and earlier allows remote authenticated users to perform unauthorized actions as an arbitrary user by using CR (\r) sequences in the service parameter to inject LOGIN and REGISTER commands with the desired username. | [email protected] | 6.5 | 1.99% | 2007-04-25 | 2026-06-16 |
| CVE-2007-2232 | The CHECK command in Cosign 2.0.1 and earlier allows remote attackers to bypass authentication requirements via CR (\r) sequences in the cosign cookie parameter. | [email protected] | 7.5 | 2.47% | 2007-04-25 | 2026-06-16 |