go-jose before 1.0.4 suffers from multiple signatures exploitation. The go-jose library supports messages with multiple signatures. However, when validating a signed message the API did not indicate which signature was valid, which could potentially lead to confusion. For example, users of the library might mistakenly read protected header values from an attached signature that was different from the one originally validated.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: hackerone
Published: 2017-03-28T02:46:00
Updated: 2024-08-06T02:42:10.637Z
Reserved: 2016-10-31T00:00:00
Link: CVE-2016-9122
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-03-28T02:59:00.260
Modified: 2024-11-21T03:00:39.583
Link: CVE-2016-9122
Redhat
No data.