Net::OAuth 0.33 之前版本的 Perl 库中,攻击者可以在签名验证过程中自行选择签名算法。 在 函数中,签名方法类是从传入消息的 参数中解析得到的。由于所有请求都必须提供 参数,因此用于验证签名的算法实际上由发送方决定,而验证方无法强制锁定特定的签名方法。 当消息指定使用 HMAC-SHA1 或 HMAC-SHA256 时,签名密钥会从 和 派生,而不是使用服务提供商(provider)部署的密钥。 如果服务提供商部署的是 RSA-SHA1 签名方案,则其仅持有消费者的公钥。根据 RFC 5849,R
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | - | 0 ~ 0.33 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet