CVE-2016-9122
Last modified
CVE-2016-9122 is a vulnerability of currently unknown severity. go-jose before 1.0.4 suffers from multiple signatures exploitation. The go-jose library supports messages with multiple signatures. EPSS estimates a 1.97% chance of exploitation in the next 30 days.
Description
go-jose before 1.0.4 suffers from multiple signatures exploitation. The go-jose library supports messages with multiple signatures. However, when validating a signed message the API did not indicate which signature was valid, which could potentially lead to confusion. For example, users of the library might mistakenly read protected header values from an attached signature that was different from the one originally validated.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Go-Jose Project | Go-Jose | <= 1.0.3 |
References
- http://www.openwall.com/lists/oss-security/2016/11/03/1Mailing List, Patch, Third Party Advisory
- https://github.com/square/go-jose/commit/2c5656adca9909843c4ff50acf1d2cf8f32da7e6Issue Tracking, Patch, Third Party Advisory
- https://hackerone.com/reports/169629Permissions Required
- http://www.openwall.com/lists/oss-security/2016/11/03/1Mailing List, Patch, Third Party Advisory
- https://github.com/square/go-jose/commit/2c5656adca9909843c4ff50acf1d2cf8f32da7e6Issue Tracking, Patch, Third Party Advisory
- https://hackerone.com/reports/169629Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-9122?
How severe is CVE-2016-9122?
How do I fix CVE-2016-9122?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-9116NULL Pointer Access in function imagetopnm of convert.c:2226…
- CVE-2016-9117NULL Pointer Access in function imagetopnm of convert.c(jp2)…
- CVE-2016-9118Heap Buffer Overflow (WRITE of size 4) in function pnmtoimag…
- CVE-2016-9119Cross-site scripting (XSS) vulnerability in the link dialogu…
- CVE-2016-9120Race condition in the ion_ioctl function in drivers/staging/…7.8
- CVE-2016-9121go-jose before 1.0.4 suffers from an invalid curve attack fo…
- CVE-2016-9123go-jose before 1.0.5 suffers from a CBC-HMAC integer overflo…
- CVE-2016-9124Revive Adserver before 3.2.3 suffers from Improper Restricti…
- CVE-2016-9125Revive Adserver before 3.2.3 suffers from session fixation, …
- CVE-2016-9126Revive Adserver before 3.2.3 suffers from persistent XSS. Us…
- CVE-2016-9127Revive Adserver before 3.2.3 suffers from Cross-Site Request…
- CVE-2016-9128Revive Adserver before 3.2.3 suffers from reflected XSS. The…
Are you affected by CVE-2016-9122?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
