Junglewise Threat Intelligence

CVE-2024-54140: sigstore-java has a vulnerability with bundle verification

CVE-2024-54140 · Severity: medium · CVSS 4 · Published 2024-12-05

Vendors: Maven.

Executive brief

sigstore-java has a vulnerability with bundle verification

Affected products

  • Maven dev.sigstore:sigstore-java

Related threats