goreleaser-1.18
1.18.2-r12
5.3
CVSS V3
malformed proposed intoto entries can cause a panic
A malformed proposed entry of the intoto/v0.0.2
type can cause a panic on a thread within the Rekor process. The thread is recovered so the client receives a 500 error message and service still continues, so the availability impact of this is minimal.
This is fixed in v1.2.0 of Rekor.
No
Discovered by OSS-Fuzz