GO-2022-0945
Dashboard / Vulnerabilities / GO-2022-0945
GO-2022-0945
Summary: Signature validation bypass in gopkg.in/square/go-jose.v1
Details: The go-jose library suffers from multiple signatures exploitation. When validating a signed message, the API did not indicate which signature was valid, which creates the potential for confusion.
References: https://www.openwall.com/lists/oss-security/2016/11/03/1, https://github.com/square/go-jose/pull/111, https://github.com/square/go-jose/commit/2c5656adca9909843c4ff50acf1d2cf8f32da7e6, https://github.com/square/go-jose/commit/789a4c4bd4c118f7564954f441b29c153ccd6a96, https://github.com/square/go-jose/commit/c7581939a3656bb65e89d64da0a52364a33d2507
Affected packages
Package
Name: gopkg.in/square/go-jose.v1
Purl: pkg:golang/gopkg.in/square/go-jose.v1
Affected ranges
Type: SEMVER
Events:
