Junglewise Threat Intelligence

CVE-2024-56138: GO-2025-3381 - notation-go's timestamp signature generation lacks certificate revocation check in github.com/notaryproject/notation-go

CVE-2024-56138 · Severity: low · CVSS 3.1 · Published 2025-01-14

Technologies: github.com/notaryproject/notation-go (Go). Vendors: Go.

Executive brief

notation-go's timestamp signature generation lacks certificate revocation check in github.com/notaryproject/notation-go

Affected products

  • Go github.com/notaryproject/notation-go

Related threats