Impact
The vulnerability in Doco‑CD arises when global OCI signature verification is enabled. An attacker with write access to the configured OCI tag can publish an artifact that contains a .doco-cd.yml file setting oci.verify: false. Because of a trust‑boundary flaw, this configuration overrides the global OCI_TRUST_POLICY.enabled setting and disables signature verification, allowing malicious or unsigned deployment content to be pipeline accepts and runs untrusted container images or services, potentially compromising the hosts the applications they serve.
Affected Systems
The Kimdre Doco‑CD GitOps continuous‑delivery tool is affected. All releases before version 0.90.1 contain the flaw; releases 0.90.1 and later include the fix that treats artifact‑contained .doco-cd.yml as untrusted and blocks undesired verification overrides.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% flaw is not listed in CISA KEV. To exploit, an attacker must have write or push permissions to the configured OCI tag. With those rights, the attacker can publish an unsigned or improperly signed artifact containing a .doco-cd.yml file setting oci.verify: false, which bypasses the global OCI_TRUST_POLICY.enabled verification, allowing untrusted deployment content to be applied.
OpenCVE Enrichment