Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-16005

Опубликовано: 04 июн. 2018
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature signs only the header values, but not the header names. This makes http-signature vulnerable to header forgery. Thus, if an attacker can intercept a request, he can swap header names and change the meaning of the request without changing the signature.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:joyent:http-signature:*:*:*:*:*:node.js:*:*
Версия до 0.9.11 (включая)

EPSS

Процентиль: 37%
0.00161
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20
CWE-347

Связанные уязвимости

CVSS3: 7.5
redhat
больше 7 лет назад

Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature signs only the header values, but not the header names. This makes http-signature vulnerable to header forgery. Thus, if an attacker can intercept a request, he can swap header names and change the meaning of the request without changing the signature.

CVSS3: 7.5
debian
больше 7 лет назад

Http-signature is a "Reference implementation of Joyent's HTTP Signatu ...

CVSS3: 7.5
github
около 7 лет назад

Header Forgery in http-signature

EPSS

Процентиль: 37%
0.00161
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20
CWE-347