sigstore kayıtları
sigstore üreticisine ait 17 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-347 Improper Verification of Cryptographic Signature6
- CWE-295 Improper Certificate Validation2
- CWE-770 Allocation of Resources Without Limits or Throttling2
- CWE-400 Uncontrolled Resource Consumption1
- CWE-706 Use of Incorrectly-Resolved Name or Reference1
- CWE-754 Improper Check for Unusual or Exceptional Conditions1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
17 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2022-35929İstismar yok | False positive signature verification in cosignsigstore · cosign · CWE-347 | Kritik9,8 | — | %0,7 | 4 Ağu 2022 |
35İzleyin | CVE-2022-35930İstismar yok | Ability to bypass attestation verification in sigstore PolicyControllersigstore · policy controller · CWE-347 | Yüksek8,8 | — | %0,7 | 4 Ağu 2022 |
30İzleyin | CVE-2024-29903İstismar yok | Cosign vulnerable to machine-wide denial of service via malicious artifactssigstore · cosign · CWE-770 | Yüksek7,5 | — | %0,9 | 10 Nis 2024 |
30İzleyin | CVE-2024-45395İstismar yok | Unbounded loop over untrusted input can lead to endless data attacksigstore · sigstore-go · CWE-835 | Yüksek7,5 | — | %0,5 | 4 Eyl 2024 |
30İzleyin | CVE-2026-31830İstismar yok | sigstore-ruby verifier returns success for DSSE bundles with mismatched in-toto subject digestsigstore · sigstore · CWE-252 | Yüksek7,5 | — | %0,4 | 10 Mar 2026 |
30İzleyin | CVE-2026-49834İstismar yok | sigstore-go: Multi-log threshold bypass via single compromised logsigstore · sigstore-go · CWE-347 | Yüksek7,5 | — | %0,2 | 17 Tem 2026 |
23İzleyin | CVE-2024-29902İstismar yok | Cosign vulnerable to system-wide denial of service via malicious attachmentssigstore · cosign · CWE-770 | Orta5,9 | — | %0,7 | 10 Nis 2024 |
22İzleyin | CVE-2022-36056İstismar yok | Vulnerabilities with blob verification in sigstore cosignsigstore · cosign · CWE-347 | Orta5,5 | — | %0,2 | 14 Eyl 2022 |
22İzleyin | CVE-2026-22703İstismar yok | Cosign verification accepts any valid Rekor entry under certain conditionssigstore · cosign · CWE-345 | Orta5,5 | — | %0,1 | 10 Oca 2026 |
22İzleyin | CVE-2024-53267İstismar yok | Vulnerability with bundle verification in sigstore-javasigstore · sigstore-java · CWE-347 | Orta5,5 | — | %0,1 | 26 Kas 2024 |
21İzleyin | CVE-2023-46737İstismar yok | Possible endless data attack from attacker-controlled registry in cosignsigstore · cosign · CWE-400 | Orta5,3 | — | %0,6 | 7 Kas 2023 |
21İzleyin | CVE-2023-47122İstismar yok | Gitsign's Rekor public keys fetched from upstream API instead of local TUF client.sigstore · gitsign · CWE-347 | Orta5,3 | — | %0,4 | 10 Kas 2023 |
21İzleyin | CVE-2026-39395İstismar yok | Cosign's verify-blob-attestation reports false positive when payload parsing failssigstore · cosign · CWE-754 | Orta5,3 | — | %0,3 | 7 Nis 2026 |
14İzleyin | CVE-2026-24122İstismar yok | Cosign Certificate Chain Expiry Validation Issue Allows Issuing Certificate Expiry to Be Overlookedsigstore · cosign · CWE-295 | Düşük3,7 | — | %0,2 | 19 Şub 2026 |
13İzleyin | CVE-2022-23649İstismar yok | Improper Certificate Validation in Cosignsigstore · cosign · CWE-295 | Düşük3,3 | — | %0,2 | 18 Şub 2022 |
8İzleyin | CVE-2024-54140İstismar yok | sigstore-java has a vulnerability with bundle verificationsigstore · sigstore-java · CWE-20 | Düşük2,1 | — | %0,2 | 5 Ara 2024 |
7İzleyin | CVE-2024-51746İstismar yok | Use of incorrect Rekor entries during verification in gitsignsigstore · gitsign · CWE-706 | Düşük1,8 | — | %0,1 | 5 Kas 2024 |
- CVE-2022-3592939İzleyin
False positive signature verification in cosign
KritikCVSS 9,8İstismar yokEPSS %1sigstore · cosign4 Ağu 2022
- CVE-2022-3593035İzleyin
Ability to bypass attestation verification in sigstore PolicyController
YüksekCVSS 8,8İstismar yokEPSS %1sigstore · policy controller4 Ağu 2022
- CVE-2024-2990330İzleyin
Cosign vulnerable to machine-wide denial of service via malicious artifacts
YüksekCVSS 7,5İstismar yokEPSS %1sigstore · cosign10 Nis 2024
- CVE-2024-4539530İzleyin
Unbounded loop over untrusted input can lead to endless data attack
YüksekCVSS 7,5İstismar yokEPSS %0sigstore · sigstore-go4 Eyl 2024
- CVE-2026-3183030İzleyin
sigstore-ruby verifier returns success for DSSE bundles with mismatched in-toto subject digest
YüksekCVSS 7,5İstismar yokEPSS %0sigstore · sigstore10 Mar 2026
- CVE-2026-4983430İzleyin
sigstore-go: Multi-log threshold bypass via single compromised log
YüksekCVSS 7,5İstismar yokEPSS %0sigstore · sigstore-go17 Tem 2026
- CVE-2024-2990223İzleyin
Cosign vulnerable to system-wide denial of service via malicious attachments
OrtaCVSS 5,9İstismar yokEPSS %1sigstore · cosign10 Nis 2024
- CVE-2022-3605622İzleyin
Vulnerabilities with blob verification in sigstore cosign
OrtaCVSS 5,5İstismar yokEPSS %0sigstore · cosign14 Eyl 2022
- CVE-2026-2270322İzleyin
Cosign verification accepts any valid Rekor entry under certain conditions
OrtaCVSS 5,5İstismar yokEPSS %0sigstore · cosign10 Oca 2026
- CVE-2024-5326722İzleyin
Vulnerability with bundle verification in sigstore-java
OrtaCVSS 5,5İstismar yokEPSS %0sigstore · sigstore-java26 Kas 2024
- CVE-2023-4673721İzleyin
Possible endless data attack from attacker-controlled registry in cosign
OrtaCVSS 5,3İstismar yokEPSS %1sigstore · cosign7 Kas 2023
- CVE-2023-4712221İzleyin
Gitsign's Rekor public keys fetched from upstream API instead of local TUF client.
OrtaCVSS 5,3İstismar yokEPSS %0sigstore · gitsign10 Kas 2023
- CVE-2026-3939521İzleyin
Cosign's verify-blob-attestation reports false positive when payload parsing fails
OrtaCVSS 5,3İstismar yokEPSS %0sigstore · cosign7 Nis 2026
- CVE-2026-2412214İzleyin
Cosign Certificate Chain Expiry Validation Issue Allows Issuing Certificate Expiry to Be Overlooked
DüşükCVSS 3,7İstismar yokEPSS %0sigstore · cosign19 Şub 2026
- CVE-2022-2364913İzleyin
Improper Certificate Validation in Cosign
DüşükCVSS 3,3İstismar yokEPSS %0sigstore · cosign18 Şub 2022
- CVE-2024-541408İzleyin
sigstore-java has a vulnerability with bundle verification
DüşükCVSS 2,1İstismar yokEPSS %0sigstore · sigstore-java5 Ara 2024
- CVE-2024-517467İzleyin
Use of incorrect Rekor entries during verification in gitsign
DüşükCVSS 1,8İstismar yokEPSS %0sigstore · gitsign5 Kas 2024