blob: ce00d3d1a1a729376462e1c6080c7d5d54d726d1 [file] [log] [blame]
id: GO-2025-3381
modules:
- module: github.com/notaryproject/notation-go
versions:
- introduced: 1.2.0-beta.1
- fixed: 1.3.0-rc.2
vulnerable_at: 1.3.0-rc.1
summary: notation-go's timestamp signature generation lacks certificate revocation check in github.com/notaryproject/notation-go
cves:
- CVE-2024-56138
ghsas:
- GHSA-45v3-38pc-874v
references:
- advisory: https://github.com/notaryproject/notation-go/security/advisories/GHSA-45v3-38pc-874v
- fix: https://github.com/notaryproject/notation-go/commit/e99be1954a15673020150c5f8800b8174cd7428d
source:
id: GHSA-45v3-38pc-874v
created: 2025-01-14T14:54:45.902402934Z
review_status: UNREVIEWED