Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-9122

Опубликовано: 28 мар. 2017
Источник: ubuntu
Приоритет: medium
CVSS2: 5
CVSS3: 7.5

Описание

go-jose before 1.0.4 suffers from multiple signatures exploitation. The go-jose library supports messages with multiple signatures. However, when validating a signed message the API did not indicate which signature was valid, which could potentially lead to confusion. For example, users of the library might mistakenly read protected header values from an attached signature that was different from the one originally validated.

РелизСтатусПримечание
devel

not-affected

1.1.0-3
esm-infra-legacy/trusty

DNE

precise

DNE

precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

released

1.0.5-1
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

xenial

DNE

Показывать по

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 9 лет назад

go-jose before 1.0.4 suffers from multiple signatures exploitation. The go-jose library supports messages with multiple signatures. However, when validating a signed message the API did not indicate which signature was valid, which could potentially lead to confusion. For example, users of the library might mistakenly read protected header values from an attached signature that was different from the one originally validated.

CVSS3: 7.5
debian
почти 9 лет назад

go-jose before 1.0.4 suffers from multiple signatures exploitation. Th ...

CVSS3: 7.5
github
больше 4 лет назад

Go JOSE Signature Validation Bypass

5 Medium

CVSS2

7.5 High

CVSS3