VDB

CVE-2023-25656

CVE-2023-25656 PUBLISHED CVSS 7.5 HIGH

notation-go is a collection of libraries for supporting Notation sign, verify, push, and pull of oci artifacts. Prior to version 1.0.0-rc.3, notation-go users will find their application using excessive memory when verifying signatures. The application will be killed, and thus availability is impacted. The problem has been patched in the release v1.0.0-rc.3. Some workarounds are available. Users can review their own trust policy file and check if the identity string contains `=#`. Meanwhile, users should only put trusted certificates in their trust stores referenced by their own trust policy files, and make sure the `authenticity` validation is set to `enforce`.

EPSS 0.44% · 63.4th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.44%
63.4th percentile

Affected Products

VendorProductVersions
notaryprojectnotation-go1.0.0-rc.3, 0.7.0, 0.8.0
github.comnotaryproject/notation-go0

Timeline

  • Feb 20, 2023 CVE Published
  • Feb 21, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 1, 2023 EPSS Score
  • May 11, 2023 EPSS Score
  • Jun 19, 2023 EPSS Score
  • Jul 29, 2023 EPSS Score
  • Sep 6, 2023 EPSS Score
  • Oct 15, 2023 EPSS Score
  • Nov 24, 2023 EPSS Score
  • Jan 2, 2024 EPSS Score
  • Feb 10, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›