CVE-2021-41087: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
(updated )
in-toto-golang is a go implementation of the in-toto framework to protect software supply chain integrity. within a trusted set of users for a layout) are able to create attestations that may bypass DISALLOW rules in the same layout.
References
Detect and mitigate CVE-2021-41087 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →