Advisories for Golang/Github.com/In-Toto/Go-Witness package

2025

go-witness is Vulnerable to Improper Verification of AWS EC2 Identity Documents

This vulnerability only affects users of the AWS attestor. Users of the AWS attestor could have unknowingly received a forged identity document. While this may seem unlikely, AWS recently issued a security bulletin about IMDS (Instance Metadata Service) impersonation.[^1] There are multiple locations where the verification of the identity document will mistakenly report a successful verification.