QID 996765
Date Published: 2024-01-23
QID 996765: GO (Go) Security Update for github.com/notaryproject/notation (GHSA-57wx-m636-g3g8)
An external actor with control of a compromised container registry can provide outdated versions of OCI artifacts, such as Images. This could lead artifact consumers with relaxed trust policies (such as permissive instead of strict) to potentially use artifacts with signatures that are no longer valid, making them susceptible to any exploits those artifacts may contain.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-57wx-m636-g3g8 for updates and patch information.
Vendor References
- GHSA-57wx-m636-g3g8 -
github.com/advisories/GHSA-57wx-m636-g3g8
CVEs related to QID 996765
Software Advisories
| Advisory ID | Software | Component | Link |
|---|