PT-2025-3196 · Unknown+1 · Notation-Go+1

Faeris95

·

Published

2025-01-13

·

Updated

2025-01-30

·

CVE-2024-56138

CVSS v3.1

4.0

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions notation-go versions prior to 1.3.0-rc.2
Description The issue arises from the failure to verify the revocation status of the certificate(s) used to generate the timestamp signature during timestamp signature generation. This oversight creates a potential for Man-in-The-Middle attacks, where an attacker could use a compromised, intermediate, or revoked leaf certificate to generate a malicious countersignature. This could lead to denial of service scenarios, particularly in CI/CD environments during signature verification processes, as the timestamp signature would fail due to the presence of a revoked certificate(s), potentially disrupting operations.
Recommendations notation-go versions prior to 1.3.0-rc.2: Upgrade to release version 1.3.0-rc.2 or later to address the issue.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2024-56138
GHSA-45V3-38PC-874V
GO-2025-3381
OPENSUSE-SU-2025:14653-1
OPENSUSE-SU-2025_0297-1
SUSE-SU-2025:0297-1

Affected Products

Suse
Notation-Go