In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Missing Authorization vulnerabilities in an interactive lesson.
Start learningUpgrade sequoia-git to version 0.6.0 or higher.
Affected versions of this package are vulnerable to Missing Authorization via the policy process. An attacker can bypass intended certificate revocation by submitting a merge request that removes a hard revocation from the signing policy, and if a maintainer merges this request, subsequent commits will not be checked against the revoked certificate. This is only exploitable if a maintainer is tricked into merging a malicious merge request that strips the hard revocation from the policy.