VDB
Sign up
HIGH8.8

GHSA-xhg5-42rf-296r

notation-go's verification bypass can cause users to verify the wrong artifact

Quick fix

GHSA-xhg5-42rf-296r — github.com/notaryproject/notation-go: upgrade to the fixed version with the command below.

go get github.com/notaryproject/notation-go@v1.0.0-rc.6

Details

### Impact An attacker who controls or compromises a registry can lead a user to verify the wrong artifact.

### Patches The problem has been fixed in the release [v1.0.0-rc.6](https://github.com/notaryproject/notation-go/releases/tag/v1.0.0-rc.6). Users should upgrade their notation-go library to [v1.0.0-rc.6](https://github.com/notaryproject/notation-go/releases/tag/v1.0.0-rc.6) or above.

### Workarounds User should use secure and trusted container registries.

### Credits The `notation` project would like to thank Adam Korczynski (@AdamKorcz) for responsibly disclosing the issue found during an security audit (facilitated by OSTIF and sponsored by CNCF) and Shiwei Zhang (@shizhMSFT), Pritesh Bandi (@priteshbandi) for root cause analysis.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/notaryproject/notation-go
Introduced in: 0Fixed in: 1.0.0-rc.6
Fixgo get github.com/notaryproject/notation-go@v1.0.0-rc.6

References