Junglewise Threat Intelligence

CVE-2022-36056: GO-2022-0998 - Improper blob verification in github.com/sigstore/cosign

CVE-2022-36056 · Severity: low · CVSS 3.1 · Published 2023-11-09

Technologies: github.com/sigstore/cosign (Go). Vendors: Go.

Executive brief

Improper blob verification in github.com/sigstore/cosign

Affected products

  • Go github.com/sigstore/cosign

Related threats