Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-9122

Опубликовано: 28 мар. 2017
Источник: debian

Описание

go-jose before 1.0.4 suffers from multiple signatures exploitation. The go-jose library supports messages with multiple signatures. However, when validating a signed message the API did not indicate which signature was valid, which could potentially lead to confusion. For example, users of the library might mistakenly read protected header values from an attached signature that was different from the one originally validated.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-gopkg-square-go-jose.v1fixed1.0.5-1package

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 9 лет назад

go-jose before 1.0.4 suffers from multiple signatures exploitation. The go-jose library supports messages with multiple signatures. However, when validating a signed message the API did not indicate which signature was valid, which could potentially lead to confusion. For example, users of the library might mistakenly read protected header values from an attached signature that was different from the one originally validated.

CVSS3: 7.5
nvd
почти 9 лет назад

go-jose before 1.0.4 suffers from multiple signatures exploitation. The go-jose library supports messages with multiple signatures. However, when validating a signed message the API did not indicate which signature was valid, which could potentially lead to confusion. For example, users of the library might mistakenly read protected header values from an attached signature that was different from the one originally validated.

CVSS3: 7.5
github
больше 4 лет назад

Go JOSE Signature Validation Bypass