VendorsNotary Projectnotation-goany version
Vulnerabilities

Notary Project notation-go any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2023-33959
Verification bypass can cause users into verifying the wrong artifact
Published 2023-06-06 · Modified
8.8EPSS 0.004
CVE-2024-23332
Client configured with permissive trust policies susceptible to rollback attack in Notary Project
Published 2024-01-19 · Modified
6.8EPSS 0.003
CVE-2023-33958
Default `maxSignatureAttempts` in `notation verify` enables an endless data attack in notation
Published 2023-06-06 · Modified
6.5EPSS 0.005
CVE-2023-33957
Denial of service from high number of artifact signatures in notation
Published 2023-06-06 · Modified
5.7EPSS 0.005
CVE-2024-51491
Process crash during CRL-based revocation check on OS using separate mount point for temp Directory in notation-go
Published 2025-01-13 · Analyzed
3.3EPSS 0.002