HIGH 8.8 Go

notation-go's verification bypass can cause users to verify the wrong artifact

GHSA-xhg5-42rf-296r · CVE-2023-33959 · GO-2023-1832

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

An attacker who controls or compromises a registry can lead a user to verify the wrong artifact.

Patches

The problem has been fixed in the release v1.0.0-rc.6. Users should upgrade their notation-go library to v1.0.0-rc.6 or above.

Workarounds

User should use secure and trusted container registries.

Credits

The notation project would like to thank Adam Korczynski (@AdamKorcz) for responsibly disclosing the issue found during an security audit (facilitated by OSTIF and sponsored by CNCF) and Shiwei Zhang (@shizhMSFT), Pritesh Bandi (@priteshbandi) for root cause analysis.

Ready to move

Start Securing

Free, no credit card | First findings in minutes