Executive brief
Improper blob verification in github.com/sigstore/cosign
Affected products
- Go github.com/sigstore/cosign
Junglewise Threat Intelligence
CVE-2022-36056 · Severity: low · CVSS 3.1 · Published 2023-11-09
Technologies: github.com/sigstore/cosign (Go). Vendors: Go.
Improper blob verification in github.com/sigstore/cosign