cve/2023/CVE-2023-33959.md

24 lines
1.2 KiB
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2023-33959](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-33959)
![](https://img.shields.io/static/v1?label=Product&message=notation-go&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20%3C%201.0.0-rc.6%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-347%3A%20Improper%20Verification%20of%20Cryptographic%20Signature&color=brighgreen)
### Description
notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry can cause users to verify the wrong artifact. The problem has been fixed in the release v1.0.0-rc.6. Users should upgrade their notation-go library to v1.0.0-rc.6 or above. Users unable to upgrade may restrict container registries to a set of secure and trusted container registries.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/anhtranquang/deps-with-cve
- https://github.com/anhtranquang/unused-deps-with-cve
- https://github.com/dattq88/PoC-unused-deps-with-cve
- https://github.com/scan-demo/deps-with-cve
- https://github.com/scan-demo/unused-deps-with-cve
- https://github.com/sec-scan-demo/deps-with-cve
- https://github.com/sec-scan-demo/unused-deps-with-cve