CVE-2024-53267: sigstore-java has vulnerability with bundle verification
(updated )
sigstore-java has insufficient verification for a situation where a validly-signed but “mismatched” bundle is presented as proof of inclusion into a transparency log
References
Detect and mitigate CVE-2024-53267 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →