CyberRota Analysis
AI-GeneratedThe vulnerability affects the Apko package manager prior to version 1.2.9 and Melange prior to version 0.50.4, allowing attackers to substitute arbitrary file contents during package installation without triggering a control hash verification failure. This could lead to the installation of malicious packages if an attacker compromises a mirror, poisons a cache, or conducts a man-in-the-middle attack. Organizations using these tools should prioritize updates to mitigate the risk of unauthorized code execution and potential system compromise.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never verified the data section hash (the actual package files that get installed). An attacker who could compromise a mirror, poison a cache, or MITM a package fetch could substitute arbitrary file contents while the control hash check still passed. Apko version 1.2.9 and melange version 0.50.4 contain a fix.