Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-9122

Опубликовано: 28 мар. 2017
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

go-jose before 1.0.4 suffers from multiple signatures exploitation. The go-jose library supports messages with multiple signatures. However, when validating a signed message the API did not indicate which signature was valid, which could potentially lead to confusion. For example, users of the library might mistakenly read protected header values from an attached signature that was different from the one originally validated.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:go-jose_project:go-jose:*:*:*:*:*:*:*:*
Версия до 1.0.3 (включая)

EPSS

Процентиль: 55%
0.00327
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 9 лет назад

go-jose before 1.0.4 suffers from multiple signatures exploitation. The go-jose library supports messages with multiple signatures. However, when validating a signed message the API did not indicate which signature was valid, which could potentially lead to confusion. For example, users of the library might mistakenly read protected header values from an attached signature that was different from the one originally validated.

CVSS3: 7.5
debian
почти 9 лет назад

go-jose before 1.0.4 suffers from multiple signatures exploitation. Th ...

CVSS3: 7.5
github
больше 4 лет назад

Go JOSE Signature Validation Bypass

EPSS

Процентиль: 55%
0.00327
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-284