Количество 4
Количество 4
CVE-2017-16005
Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature signs only the header values, but not the header names. This makes http-signature vulnerable to header forgery. Thus, if an attacker can intercept a request, he can swap header names and change the meaning of the request without changing the signature.
CVE-2017-16005
Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature signs only the header values, but not the header names. This makes http-signature vulnerable to header forgery. Thus, if an attacker can intercept a request, he can swap header names and change the meaning of the request without changing the signature.
CVE-2017-16005
Http-signature is a "Reference implementation of Joyent's HTTP Signatu ...
GHSA-q257-vv4p-fg92
Header Forgery in http-signature
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2017-16005 Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature signs only the header values, but not the header names. This makes http-signature vulnerable to header forgery. Thus, if an attacker can intercept a request, he can swap header names and change the meaning of the request without changing the signature. | CVSS3: 7.5 | 0% Низкий | больше 7 лет назад | |
CVE-2017-16005 Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature signs only the header values, but not the header names. This makes http-signature vulnerable to header forgery. Thus, if an attacker can intercept a request, he can swap header names and change the meaning of the request without changing the signature. | CVSS3: 7.5 | 0% Низкий | больше 7 лет назад | |
CVE-2017-16005 Http-signature is a "Reference implementation of Joyent's HTTP Signatu ... | CVSS3: 7.5 | 0% Низкий | больше 7 лет назад | |
GHSA-q257-vv4p-fg92 Header Forgery in http-signature | CVSS3: 7.5 | 0% Низкий | около 7 лет назад |
Уязвимостей на страницу