Standardseverity: HighDraft
CAPEC-461Web Services API Signature Forgery Leveraging Hash Function Extension Weakness
Abstraction
Standard
Status
Draft
Severity
High
Description
An adversary utilizes a hash function extension/padding weakness, to modify the parameters passed to the web service requesting authentication by generating their own call in order to generate a legitimate signature hash (as described in the notes), without knowledge of the secret token sometimes provided by the web service.
Related weaknesses· 2
Related attack patterns· 1
Exploits2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Use of Weak Hashcwe-328 | 100% | live |
| Weakness | Authentication Bypass by Spoofingcwe-290 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.