Executive brief
Improper verification of signature attestations in github.com/sigstore/cosign
Affected products
- Go github.com/sigstore/cosign
Junglewise Threat Intelligence
CVE-2022-35929 · Severity: low · CVSS 3.1 · Published 2023-11-09
Technologies: github.com/sigstore/cosign (Go). Vendors: Go.
Improper verification of signature attestations in github.com/sigstore/cosign