cve/2023/CVE-2023-33959.md
2024-05-28 08:49:17 +00:00

1.3 KiB

CVE-2023-33959

Description

notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry can cause users to verify the wrong artifact. The problem has been fixed in the release v1.0.0-rc.6. Users should upgrade their notation-go library to v1.0.0-rc.6 or above. Users unable to upgrade may restrict container registries to a set of secure and trusted container registries.

POC

Reference

No PoCs from references.

Github