Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-16005

Опубликовано: 07 июн. 2018
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature signs only the header values, but not the header names. This makes http-signature vulnerable to header forgery. Thus, if an attacker can intercept a request, he can swap header names and change the meaning of the request without changing the signature.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8nodejs-http-signatureWill not fix
Red Hat Mobile Application Platform 4nodejs-http-signatureNot affected
Red Hat OpenShift Enterprise 3nodejs-http-signatureNot affected
Red Hat Software Collectionsrh-nodejs4-nodejs-http-signatureNot affected
Red Hat Software Collectionsrh-nodejs6-nodejs-http-signatureNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-88
https://bugzilla.redhat.com/show_bug.cgi?id=1588846nodejs-http-signature: HTTP header forgery

EPSS

Процентиль: 37%
0.00161
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 7 лет назад

Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature signs only the header values, but not the header names. This makes http-signature vulnerable to header forgery. Thus, if an attacker can intercept a request, he can swap header names and change the meaning of the request without changing the signature.

CVSS3: 7.5
debian
больше 7 лет назад

Http-signature is a "Reference implementation of Joyent's HTTP Signatu ...

CVSS3: 7.5
github
около 7 лет назад

Header Forgery in http-signature

EPSS

Процентиль: 37%
0.00161
Низкий

7.5 High

CVSS3