GHSA-xhg5-42rf-296r
notation-go's verification bypass can cause users to verify the wrong artifact
Quick fix
GHSA-xhg5-42rf-296r — github.com/notaryproject/notation-go: upgrade to the fixed version with the command below.
go get github.com/notaryproject/notation-go@v1.0.0-rc.6Details
### Impact An attacker who controls or compromises a registry can lead a user to verify the wrong artifact.
### Patches The problem has been fixed in the release [v1.0.0-rc.6](https://github.com/notaryproject/notation-go/releases/tag/v1.0.0-rc.6). Users should upgrade their notation-go library to [v1.0.0-rc.6](https://github.com/notaryproject/notation-go/releases/tag/v1.0.0-rc.6) or above.
### Workarounds User should use secure and trusted container registries.
### Credits The `notation` project would like to thank Adam Korczynski (@AdamKorcz) for responsibly disclosing the issue found during an security audit (facilitated by OSTIF and sponsored by CNCF) and Shiwei Zhang (@shizhMSFT), Pritesh Bandi (@priteshbandi) for root cause analysis.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.0.0-rc.6go get github.com/notaryproject/notation-go@v1.0.0-rc.6References
- https://github.com/notaryproject/notation-go/security/advisories/GHSA-xhg5-42rf-296r[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-33959[ADVISORY]
- https://github.com/notaryproject/notation-go/commit/39c8ed050a65cca3f3f308534acb612096735a64[WEB]
- https://github.com/notaryproject/notation-go/commit/eba60f5aed9c9e05dee55324423c95fe34700b4c[WEB]
- https://github.com/notaryproject/notation-go[PACKAGE]
- https://github.com/notaryproject/notation-go/releases/tag/v1.0.0-rc.6[WEB]