agent-manifest is vulnerable to Improper Certificate Validation
59
Medium Risk
The TPM quote verification routine builds the attestation-key certificate chain without enforcing certificate validity periods, CA basic constraints, or key-usage certificate-signing restrictions. Expired, not-yet-valid, or non-CA intermediate certificates are accepted as long as the terminal certificate fingerprint matches a trusted root. An appraisal can then report a stronger certificate-backed result than the underlying evidence supports. The fix enforces validity windows and issuer authorization when validating the chain.
You are affected if you are using a version that falls within the vulnerable range and you verify TPM quotes whose attestation-key certificate chain is supplied by an untrusted party.
agent-manifest is vulnerable to Improper Certificate Validation in versions 0.0.1 - 0.11.2.
Upgrade the agent-manifest library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.