Linuxfoundation

Sigstore Timestamp Authority

3 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.45%
  • Veröffentlicht 17.07.2026 18:16:41
  • Zuletzt bearbeitet 30.07.2026 14:14:05

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request path r.URL.Path and raw HTTP request method r.Method as Prometheus labels for latency and request co...

  • EPSS 0.1%
  • Veröffentlicht 14.04.2026 23:41:47
  • Zuletzt bearbeitet 23.04.2026 17:19:13

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Versions 2.0.5 and below contain an authorization bypass vulnerability in the VerifyTimestampResponse function. VerifyTimestampResponse correctly verifies the certificate chai...

  • EPSS 0.45%
  • Veröffentlicht 04.12.2025 22:37:13
  • Zuletzt bearbeitet 17.03.2026 20:38:33

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.0.3, Function api.ParseJSONRequest currently splits (via a call to strings.Split) an optionally-provided OID (which is untrusted data) on periods. Similarly, functi...