blob: ea194b032e71103d264217a42b06f0668011fdfb [file] [log] [blame]
id: GO-2023-1829
modules:
- module: github.com/notaryproject/notation
versions:
- fixed: 1.0.0-rc.6
vulnerable_at: 1.0.0-rc.5
summary: Notation vulnerable to denial of service from high number of artifact signatures in github.com/notaryproject/notation
cves:
- CVE-2023-33957
ghsas:
- GHSA-9m3v-v4r5-ppx7
references:
- advisory: https://github.com/notaryproject/notation/security/advisories/GHSA-9m3v-v4r5-ppx7
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2023-33957
- fix: https://github.com/notaryproject/notation/commit/ed22fde52f6d70ae0b53521bd28c9ccafa868c24
- web: https://github.com/notaryproject/notation/releases/tag/v1.0.0-rc.6
source:
id: GHSA-9m3v-v4r5-ppx7
created: 2024-08-20T11:47:02.312148-04:00
review_status: UNREVIEWED
unexcluded: EFFECTIVELY_PRIVATE