All 4 CVE vulnerabilities found in notation-go, with AI-generated Chinese analysis, references, and POCs.
Vendor: notaryproject
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-51491 | Process crash during CRL-based revocation check on OS using separate mount point for temp Directory in notation-go CWE-703 | 3.3 | Low | 2025-01-13 |
| CVE-2024-56138 | Timestamp signature generation lacks certificate revocation check in notion-go CWE-299 | 4.0 | Medium | 2025-01-13 |
| CVE-2023-33959 | Verification bypass can cause users into verifying the wrong artifact CWE-347 | 8.4 | High | 2023-06-06 |
| CVE-2023-25656 | notation-go has excessive memory allocation on verification CWE-770 | 7.5 | High | 2023-02-20 |
All 4 known CVE vulnerabilities affecting notation-go with full Chinese analysis, references, and POCs where available.