GHSA-785h-hrf7-gqxc
HIGHCVE-2015-9258In Docker Notary before 0.1, gotuf/signed/verify.go has a Signature Algorithm Not Matched to Key vulnerability. Because an attacker controls the field specifying the signature algorithm, they might (for example) be able to forge a signature by forcing a misinterpretation of an RSA-PSS key as Ed25519 elliptic-curve data.
- Affected
- < 0.1.0
- Fixed in
- 0.1.0
- Weakness
- CWE-347
- Published
- 2022-05-14
- Source
- github