CVE-2024-53267 | sigstore-java up to 1.0.x KeylessVerifier.verify signature verification (GHSA-q4xm-6fjc-5f6w)
A vulnerability was found in sigstore-java up to 1.0.x. It has been classified as problematic. Affected is the function KeylessVerifier.verify. The manipulation leads to improper verification of cryptographic signature.
This vulnerability is traded as CVE-2024-53267. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.