All vulnerabilities

GHSA-9R4W-JG96-92MV

go · github.com/google/go-attestation

Summary

Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()

References