Description
Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature signs only the header values, but not the header names. This makes http-signature vulnerable to header forgery. Thus, if an attacker can intercept a request, he can swap header names and change the meaning of the request without changing the signature.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0766 | Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature signs only the header values, but not the header names. This makes http-signature vulnerable to header forgery. Thus, if an attacker can intercept a request, he can swap header names and change the meaning of the request without changing the signature. |
Github GHSA |
GHSA-q257-vv4p-fg92 | Header Forgery in http-signature |
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-09-16T19:19:33.991Z
Reserved: 2017-10-29T00:00:00.000Z
Link: CVE-2017-16005
No data.
Status : Modified
Published: 2018-06-04T19:29:00.523
Modified: 2024-11-21T03:15:39.063
Link: CVE-2017-16005
OpenCVE Enrichment
No data.
EUVD
Github GHSA