Executive brief
sigstore-java has a vulnerability with bundle verification
Affected products
- Maven dev.sigstore:sigstore-java
Junglewise Threat Intelligence
CVE-2024-54140 · Severity: medium · CVSS 4 · Published 2024-12-05
Vendors: Maven.
sigstore-java has a vulnerability with bundle verification