High severity8.3NVD Advisory· Published Jun 6, 2023· Updated Jun 17, 2026
CVE-2023-33959
CVE-2023-33959
Description
notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry can cause users to verify the wrong artifact. The problem has been fixed in the release v1.0.0-rc.6. Users should upgrade their notation-go library to v1.0.0-rc.6 or above. Users unable to upgrade may restrict container registries to a set of secure and trusted container registries.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/notaryproject/notation-goGo | < 1.0.0-rc.6 | 1.0.0-rc.6 |
Affected products
22cpe:2.3:a:notaryproject:notation-go:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:notaryproject:notation-go:*:*:*:*:*:*:*:*range: <1.0.0
- cpe:2.3:a:notaryproject:notation-go:1.0.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:notaryproject:notation-go:1.0.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:notaryproject:notation-go:1.0.0:rc3:*:*:*:*:*:*
- cpe:2.3:a:notaryproject:notation-go:1.0.0:rc4:*:*:*:*:*:*
- cpe:2.3:a:notaryproject:notation-go:1.0.0:rc5:*:*:*:*:*:*
- (no CPE)range: < 1.0.0-rc.6
- osv-coords15 versionspkg:apk/chainguard/kyvernopkg:apk/chainguard/kyverno-background-controllerpkg:apk/chainguard/kyverno-cleanup-controllerpkg:apk/chainguard/kyverno-clipkg:apk/chainguard/kyverno-init-containerpkg:apk/chainguard/kyverno-reports-controllerpkg:apk/chainguard/zotpkg:apk/wolfi/kyvernopkg:apk/wolfi/kyverno-background-controllerpkg:apk/wolfi/kyverno-cleanup-controllerpkg:apk/wolfi/kyverno-clipkg:apk/wolfi/kyverno-init-containerpkg:apk/wolfi/kyverno-reports-controllerpkg:apk/wolfi/zotpkg:golang/github.com/notaryproject/notation-go
< 1.11.0-r1+ 14 more
- (no CPE)range: < 1.11.0-r1
- (no CPE)range: < 1.11.0-r1
- (no CPE)range: < 1.11.0-r1
- (no CPE)range: < 1.11.0-r1
- (no CPE)range: < 1.11.0-r1
- (no CPE)range: < 1.11.0-r1
- (no CPE)range: < 2.1.2-r7
- (no CPE)range: < 1.11.0-r1
- (no CPE)range: < 1.11.0-r1
- (no CPE)range: < 1.11.0-r1
- (no CPE)range: < 1.11.0-r1
- (no CPE)range: < 1.11.0-r1
- (no CPE)range: < 1.11.0-r1
- (no CPE)range: < 2.1.2-r7
- (no CPE)range: < 1.0.0-rc.6
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-xhg5-42rf-296rghsaADVISORY
- github.com/notaryproject/notation-go/security/advisories/GHSA-xhg5-42rf-296rnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-33959ghsaADVISORY
- github.com/notaryproject/notation-go/commit/39c8ed050a65cca3f3f308534acb612096735a64ghsaWEB
- github.com/notaryproject/notation-go/commit/eba60f5aed9c9e05dee55324423c95fe34700b4cghsaWEB
- github.com/notaryproject/notation-go/releases/tag/v1.0.0-rc.6ghsaWEB
News mentions
0No linked articles in our index yet.