Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

WS-2017-0266 (Low) detected in http-signature-0.10.1.tgz #67

Open
wsghe bot opened this issue Jan 13, 2022 · 0 comments
Open

WS-2017-0266 (Low) detected in http-signature-0.10.1.tgz #67

wsghe bot opened this issue Jan 13, 2022 · 0 comments
Labels
security vulnerability Security vulnerability detected by WhiteSource

Comments

@wsghe
Copy link

wsghe bot commented Jan 13, 2022

WS-2017-0266 - Low Severity Vulnerability

Vulnerable Library - http-signature-0.10.1.tgz

Reference implementation of Joyent's HTTP Signature scheme.

Library home page: https://registry.npmjs.org/http-signature/-/http-signature-0.10.1.tgz

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/zaproxy/node_modules/http-signature/package.json

Dependency Hierarchy:

  • zaproxy-0.2.0.tgz (Root Library)
    • request-2.36.0.tgz
      • http-signature-0.10.1.tgz (Vulnerable Library)

Found in HEAD commit: cf912e826f09ac42f1452743dde64dc7a5b425f5

Found in base branch: master

Vulnerability Details

http-signature before version 1.0.0 are vulnerable to timing attack, which may lead to information disclosure.

Publish Date: 2015-01-22

URL: WS-2017-0266

CVSS 3 Score Details (3.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Adjacent
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: TritonDataCenter/node-http-signature#36

Release Date: 2015-01-22

Fix Resolution: 1.0.0

@wsghe wsghe bot added the security vulnerability Security vulnerability detected by WhiteSource label Jan 13, 2022
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
security vulnerability Security vulnerability detected by WhiteSource
Projects
None yet
Development

No branches or pull requests

0 participants