| id: GO-2025-3382 |
| modules: |
| - module: github.com/notaryproject/notation-go |
| versions: |
| - introduced: 1.3.0-rc.1 |
| - fixed: 1.3.0-rc.2 |
| vulnerable_at: 1.3.0-rc.1 |
| summary: |- |
| notation-go has an OS error when setting CRL cache leads to denial of signature |
| verification in github.com/notaryproject/notation-go |
| cves: |
| - CVE-2024-51491 |
| ghsas: |
| - GHSA-qjh3-4j3h-vmwp |
| references: |
| - advisory: https://github.com/notaryproject/notation-go/security/advisories/GHSA-qjh3-4j3h-vmwp |
| - fix: https://github.com/notaryproject/notation-go/commit/3c3302258ad510fbca2f8a73731569d91f07d196 |
| source: |
| id: GHSA-qjh3-4j3h-vmwp |
| created: 2025-01-14T14:55:56.209180732Z |
| review_status: UNREVIEWED |