Vulnerability Report: GO-2025-3381
- CVE-2024-56138, GHSA-45v3-38pc-874v
- Affects: github.com/notaryproject/notation-go
- Published: Jan 14, 2025
- Unreviewed
notation-go's timestamp signature generation lacks certificate revocation check in github.com/notaryproject/notation-go
For detailed information about this vulnerability, visit https://github.com/notaryproject/notation-go/security/advisories/GHSA-45v3-38pc-874v.
Affected Modules
-
PathGo Versions
-
from v1.2.0-beta.1 before v1.3.0-rc.2
Aliases
References
- https://github.com/notaryproject/notation-go/security/advisories/GHSA-45v3-38pc-874v
- https://github.com/notaryproject/notation-go/commit/e99be1954a15673020150c5f8800b8174cd7428d
- https://vuln.go.dev/ID/GO-2025-3381.json
Feedback
This report is unreviewed. It was automatically generated from a third-party source and its details have not been verified by the Go team.
See anything missing or incorrect?
Suggest an edit to this report.