Skip to content

Update http-signature to fix timing attacks against signature verification on version 4.3.X #1738

@NerminImamovic

Description

@NerminImamovic
  • Used appropriate template for the issue type
  • Searched both open and closed issues for duplicates of this issue
  • Title adequately and concisely reflects the feature or the bug

Bug Report

Restify Version

4.3.x

Node.js Version

does not matter

Expected behaviour

Restify should be free of known security vulnerabilities.

Actual behaviour

Restify uses an old version of http-signature that has a known vulnerability

"http-signature": "^0.11.0"

This is fixed in http-signature 1.0.0 (latest versions is 1.2.0)

See joyent/node-http-signature@78ab1da

It is corrected in #1388 for version 5.x.

Repro case

n/a

Cause

Are you willing and able to fix this?

Yes

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions