Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-16005

EPSS 0.16% · P36
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2017-16005

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature signs only the header values, but not the header names. This makes http-signature vulnerable to header forgery. Thus, if an attacker can intercept a request, he can swap header names and change the meaning of the request without changing the signature.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
输入验证不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
Http-signature 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Http-signature是一个包括了具有Joyent HTTP签名方案的客户端和服务器组件的库。 Http-signature 0.9.11及之前版本中存在安全漏洞。攻击者可通过拦截请求利用该漏洞在不更改签名的情况下替换包头名并更改请求。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
HackerOnehttp-signature node module <=0.9.11 -

II. Public POCs for CVE-2017-16005

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-16005

登录查看更多情报信息。

Same Patch Batch · HackerOne · 2018-06-04 · 98 CVEs total

CVE-2017-16017Sanitize-html 跨站脚本漏洞
CVE-2017-16008i18next 跨站脚本漏洞
CVE-2017-0930augustine 路径遍历漏洞
CVE-2017-0928html-janitor 安全漏洞
CVE-2016-10697react-native-baidu-voice-synthesizer 安全漏洞
CVE-2016-10696windows-latestchromedriver 安全漏洞
CVE-2016-10695npm-test-sqlite3-trunk 安全漏洞
CVE-2017-0931html-janitor 跨站脚本漏洞
CVE-2017-16015Forms 跨站脚本漏洞
CVE-2017-16016Sanitize-html 跨站脚本漏洞
CVE-2017-16014Http-proxy 安全漏洞
CVE-2017-16018Restify 跨站脚本漏洞
CVE-2017-16019GitBook online reader 跨站脚本漏洞
CVE-2017-16020Summit 安全漏洞
CVE-2017-16021uri-js 安全漏洞
CVE-2017-16022Morris.js 跨站脚本漏洞
CVE-2017-16023Decamelize 安全漏洞
CVE-2017-16024sync-exec 安全漏洞
CVE-2017-16025Nes 安全漏洞
CVE-2017-16026Request 安全漏洞

Showing top 20 of 98 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2017-16005

No comments yet


Leave a comment