Executive brief
notation-go's timestamp signature generation lacks certificate revocation check in github.com/notaryproject/notation-go
Affected products
- Go github.com/notaryproject/notation-go
Junglewise Threat Intelligence
CVE-2024-56138 · Severity: low · CVSS 3.1 · Published 2025-01-14
Technologies: github.com/notaryproject/notation-go (Go). Vendors: Go.
notation-go's timestamp signature generation lacks certificate revocation check in github.com/notaryproject/notation-go