Sigstore
Sigstore-java: vulnerabilidades y CVE
Sigstore-java tiene 3 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE3
Últimos 12 meses1
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-48791 | Baja (2) | 0.07% | — | 13 ago 2026 | sigstore-java is a sigstore java client for interacting with sigstore infrastructure. Version 2.0.0 erroneously removed verification of the integrated (Rekor entry) time) against the Fulcio certificate. Version 2.1.0… |
| CVE-2024-54140 | Baja (2.1) | 0.21% | — | 5 dic 2024 | sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient verification for a situation where a bundle provides a invalid signature for a checkpoint. This bug… |
| CVE-2024-53267 | Media (5.5) | 0.10% | — | 26 nov 2024 | sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient verification for a situation where a validly-signed but "mismatched" bundle is presented as proof of… |