PT-2023-24598 · Notation · Notation
Adam Korczynski
+1
·
Published
2023-06-06
·
Updated
2024-08-20
·
CVE-2023-33958
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
notation versions prior to v1.0.0-rc.6
Description
An attacker who has compromised a registry and added a high number of signatures to an artifact can cause denial of service of services on the machine, if a user runs
notation verify command on the same machine. This issue can be exploited by making the registry serve an infinite number of signatures for the artifact. The maxSignatureAttempts in notation verify enables this endless data attack.Recommendations
For notation versions prior to v1.0.0-rc.6, upgrade the notation packages to v1.0.0-rc.6 or above.
As a temporary workaround, consider restricting container registries to a set of secure and trusted container registries until a patch is applied.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Notation