Improper blob verification in github.com/sigstore/cosign
{
"review_status": "REVIEWED",
"url": "https://pkg.go.dev/vuln/GO-2022-0998"
}{
"imports": [
{
"symbols": [
"VerifyAttestationCommand.Exec",
"VerifyBlobCmd",
"VerifyCommand.Exec",
"signatures",
"verifyRekorBundle",
"verifyRekorEntry",
"verifySigByUUID"
],
"path": "github.com/sigstore/cosign/cmd/cosign/cli/verify"
},
{
"symbols": [
"TLogUpload",
"TLogUploadInTotoAttestation",
"VerifyBundle",
"VerifyImageAttestations",
"VerifyImageSignature",
"VerifyImageSignatures",
"VerifyLocalImageAttestations",
"VerifyLocalImageSignatures",
"VerifySET",
"VerifyTLogEntry"
],
"path": "github.com/sigstore/cosign/pkg/cosign"
}
]
}