- EPSS 0.01%
- Veröffentlicht 13.01.2025 22:15:14
- Zuletzt bearbeitet 13.01.2025 22:15:14
notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. This issue was identified during Quarkslab's audit of the timestamp feature. During the timestamp signature generation, the r...
CVE-2024-51491
- EPSS 0.03%
- Veröffentlicht 13.01.2025 22:15:13
- Zuletzt bearbeitet 05.09.2025 15:42:25
notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. The issue was identified during Quarkslab's security audit on the Certificate Revocation List (CRL) based revocation check fe...
CVE-2024-23332
- EPSS 0.04%
- Veröffentlicht 19.01.2024 23:15:07
- Zuletzt bearbeitet 21.11.2024 08:57:31
The Notary Project is a set of specifications and tools intended to provide a cross-industry standard for securing software supply chains by using authentic container images and other OCI artifacts. An external actor with control of a compromised con...
CVE-2023-33957
- EPSS 0.06%
- Veröffentlicht 06.06.2023 19:15:12
- Zuletzt bearbeitet 21.11.2024 08:06:17
notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry and added a high number of signatures to an artifact can cause denial of service of services on the machine, if a user runs notat...
CVE-2023-33958
- EPSS 0.09%
- Veröffentlicht 06.06.2023 19:15:12
- Zuletzt bearbeitet 21.11.2024 08:06:17
notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry and added a high number of signatures to an artifact can cause denial of service of services on the machine, if a user runs notat...
CVE-2023-33959
- EPSS 0.14%
- Veröffentlicht 06.06.2023 19:15:12
- Zuletzt bearbeitet 21.11.2024 08:06:17
notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry can cause users to verify the wrong artifact. The problem has been fixed in the release v1.0.0-rc.6. Users should upgrade their n...
CVE-2023-25656
- EPSS 0.16%
- Veröffentlicht 20.02.2023 16:15:10
- Zuletzt bearbeitet 21.11.2024 07:49:52
notation-go is a collection of libraries for supporting Notation sign, verify, push, and pull of oci artifacts. Prior to version 1.0.0-rc.3, notation-go users will find their application using excessive memory when verifying signatures. The applicati...