CVE-2024-54140: sigstore-java has a vulnerability with bundle verification
(updated )
sigstore-java has insufficient verification for a situation where a bundle provides a invalid signature for a checkpoint.
References
- github.com/advisories/GHSA-jp26-88mw-89qr
- github.com/sigstore/sigstore-conformance/pull/139
- github.com/sigstore/sigstore-java
- github.com/sigstore/sigstore-java/commit/23fb4885e6704a5df4977f7acf253a745349edf9
- github.com/sigstore/sigstore-java/security/advisories/GHSA-jp26-88mw-89qr
- nvd.nist.gov/vuln/detail/CVE-2024-54140
Detect and mitigate CVE-2024-54140 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →