agent-manifest is vulnerable to Insufficient Verification of Data Authenticity
31
Low Risk
The human-in-the-loop approval approval_method field is not part of the signed pre-image, so it can be altered after signing without invalidating the approval signature. Changing a software-key approval to a hardware-key value keeps the original signature valid while raising the reported approval strength. This can satisfy method-sufficiency checks at conformance level 2 that the original approval should not meet. The fix binds the approval method into the authenticated approval data.
You are affected if you are using a version that falls within the vulnerable range and you rely on level-2 human-in-the-loop approval-method sufficiency checks.
agent-manifest is vulnerable to Insufficient Verification of Data Authenticity in versions 0.0.1 - 0.11.2.
Upgrade the agent-manifest library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.