Authorization Bypass Through User-Controlled Key The advisory has been revoked - it doesn't affect any version of package trustee-guest-components  (opens in a new tab)


Threat Intelligence

EPSS
0.33% (25th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CENTOS9-TRUSTEEGUESTCOMPONENTS-13532332
  • published11 Oct 2025
  • disclosed9 Oct 2025

Introduced: 9 Oct 2025

CVE-2025-61779  (opens in a new tab)
CWE-639  (opens in a new tab)

Amendment

The Centos security team deemed this advisory irrelevant for Centos:9.

NVD Description

Note: Versions mentioned in the description apply only to the upstream trustee-guest-components package and not the trustee-guest-components package as distributed by Centos.

Confidential Containers's Trustee project contains tools and components for attesting confidential guests and providing secrets to them. In versions prior to 0.15.0, the attestation-policy endpoint didn't check if the kbs-client submitting the request was actually authenticated (had the right key). This allowed any kbs-client to actually change the attestation policy. Version 0.15.0 fixes the issue.