VDB
GO-2024-2472
GO-2024-2472
PUBLISHED
Go package github.com/notaryproject/notation configured with permissive trust policies potentially susceptible to rollback attack from compromised registry
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | notaryproject/notation | 0, 0 |
| chainguard | xeol | 0 |
| wolfi | xeol | 0, 0, 0 |
| chainguard | xeol-fips | 0 |
Timeline
- Jun 28, 2024 CVE Published
- Mar 3, 2026 CVE Updated
- May 18, 2026 Security Advisory