GHSA-57wx-m636-g3g8
MEDIUMCVE-2024-23332An external actor with control of a compromised container registry can provide outdated versions of OCI artifacts, such as Images. This could lead artifact consumers with relaxed trust policies (such as permissive instead of strict) to potentially use artifacts with signatures that are no longer valid, making them susceptible to any exploits those artifacts may contain.
- Affected
- >=0
- Fixed in
- not stated
- Published
- 2024-01-19
- Source
- github