Vulnerability Report: GO-2022-0945

The go-jose library suffers from multiple signatures exploitation. When validating a signed message, the API did not indicate which signature was valid, which creates the potential for confusion.

For detailed information about this vulnerability, visit https://www.openwall.com/lists/oss-security/2016/11/03/1.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL