CWE-347
AllowedImproper Verification of Cryptographic Signature
Abstraction: Base · Status: Draft
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
1422 vulnerabilities reference this CWE, most recent first.
GHSA-VR9W-FP6C-VJ58
Vulnerability from github – Published: 2025-04-16 18:31 – Updated: 2025-04-16 18:31A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker with valid administrative credentials to execute arbitrary commands as root on the underlying operating system.
This vulnerability is due to insufficient integrity checks within device backup files. An attacker with valid administrative credentials could exploit this vulnerability by crafting a malicious backup file and restoring it to an affected device. A successful exploit could allow the attacker to obtain shell access on the underlying operating system with the privileges of root.
{
"affected": [],
"aliases": [
"CVE-2025-20178"
],
"database_specific": {
"cwe_ids": [
"CWE-347"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-16T16:15:29Z",
"severity": "MODERATE"
},
"details": "A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker with valid administrative credentials to execute arbitrary commands as root on the underlying operating system.\n\n\nThis vulnerability is due to insufficient integrity checks within device backup files. An attacker with valid administrative credentials could exploit this vulnerability by crafting a malicious backup file and restoring it to an affected device. A successful exploit could allow the attacker to obtain shell access on the underlying operating system with the privileges of root.",
"id": "GHSA-vr9w-fp6c-vj58",
"modified": "2025-04-16T18:31:50Z",
"published": "2025-04-16T18:31:50Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20178"
},
{
"type": "WEB",
"url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sna-prvesc-4BQmK33Z"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-VRWH-33VR-JG7W
Vulnerability from github – Published: 2026-06-26 21:32 – Updated: 2026-06-26 21:32The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application.
{
"affected": [],
"aliases": [
"CVE-2024-23581"
],
"database_specific": {
"cwe_ids": [
"CWE-1104",
"CWE-347"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-06-26T21:16:32Z",
"severity": "MODERATE"
},
"details": "The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application.",
"id": "GHSA-vrwh-33vr-jg7w",
"modified": "2026-06-26T21:32:18Z",
"published": "2026-06-26T21:32:18Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23581"
},
{
"type": "WEB",
"url": "https://support.hcl-software.com/csm?id=kb_article\u0026sysparm_article=KB0131417"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-VW3M-3X7W-24G8
Vulnerability from github – Published: 2026-09-10 18:31 – Updated: 2026-09-10 18:31passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to the assertion consumer service endpoint to receive authenticated profiles without valid signatures.
{
"affected": [],
"aliases": [
"CVE-2026-89042"
],
"database_specific": {
"cwe_ids": [
"CWE-347"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-09-10T18:18:15Z",
"severity": "CRITICAL"
},
"details": "passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to the assertion consumer service endpoint to receive authenticated profiles without valid signatures.",
"id": "GHSA-vw3m-3x7w-24g8",
"modified": "2026-09-10T18:31:50Z",
"published": "2026-09-10T18:31:50Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89042"
},
{
"type": "WEB",
"url": "https://github.com/krakenjs/passport-saml-encrypted/issues/29"
},
{
"type": "WEB",
"url": "https://github.com/krakenjs/passport-saml-encrypted"
},
{
"type": "WEB",
"url": "https://github.com/krakenjs/passport-saml-encrypted/blob/v0.1.13/lib/saml.js#L296"
},
{
"type": "WEB",
"url": "https://github.com/krakenjs/passport-saml-encrypted/blob/v0.1.13/lib/saml.js#L321"
},
{
"type": "WEB",
"url": "https://www.vulncheck.com/advisories/passport-saml-encrypted-through-0.1.13-authentication-bypass-via-missing-signature-verification"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-VW9V-MPFH-QWG3
Vulnerability from github – Published: 2026-08-11 09:32 – Updated: 2026-09-18 00:31A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application.
{
"affected": [],
"aliases": [
"CVE-2026-15556"
],
"database_specific": {
"cwe_ids": [
"CWE-347"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-08-11T09:17:12Z",
"severity": "HIGH"
},
"details": "A flaw was found in Picketlink\u0027s SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application.",
"id": "GHSA-vw9v-mpfh-qwg3",
"modified": "2026-09-18T00:31:05Z",
"published": "2026-08-11T09:32:35Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15556"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:53644"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:53645"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:53646"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:53806"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2026-15556"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2483121"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-VWJ8-GGFW-43W9
Vulnerability from github – Published: 2024-12-19 00:37 – Updated: 2024-12-19 00:37A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage OneNote's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application's permissions.
{
"affected": [],
"aliases": [
"CVE-2024-41159"
],
"database_specific": {
"cwe_ids": [
"CWE-347"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-18T23:15:08Z",
"severity": "HIGH"
},
"details": "A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage OneNote\u0027s access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application\u0027s permissions.",
"id": "GHSA-vwj8-ggfw-43w9",
"modified": "2024-12-19T00:37:35Z",
"published": "2024-12-19T00:37:35Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41159"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1975"
},
{
"type": "WEB",
"url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1975"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-VX7R-7H24-RM89
Vulnerability from github – Published: 2022-05-24 17:46 – Updated: 2022-05-24 17:46Union Pay up to 3.4.93.4.9, for android, contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability, allows attackers to shop for free in merchants' websites and mobile apps, via a crafted authentication code (MAC) which is generated based on a secret key which is NULL.
{
"affected": [],
"aliases": [
"CVE-2020-36284"
],
"database_specific": {
"cwe_ids": [
"CWE-347"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2021-04-06T16:15:00Z",
"severity": "HIGH"
},
"details": "Union Pay up to 3.4.93.4.9, for android, contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability, allows attackers to shop for free in merchants\u0027 websites and mobile apps, via a crafted authentication code (MAC) which is generated based on a secret key which is NULL.",
"id": "GHSA-vx7r-7h24-rm89",
"modified": "2022-05-24T17:46:35Z",
"published": "2022-05-24T17:46:35Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-36284"
},
{
"type": "WEB",
"url": "https://www.dropbox.com/s/6smwnbrp0kgsgrc/poc_code.py?dl=0"
},
{
"type": "WEB",
"url": "https://www.dropbox.com/s/czbkdr73tclq2nr/UnionPay_Vulnerability_Report.txt?dl=0"
},
{
"type": "WEB",
"url": "http://mobitec.ie.cuhk.edu.hk/cve_2020"
}
],
"schema_version": "1.4.0",
"severity": []
}
GHSA-VX8M-6FHW-PCCW
Vulnerability from github – Published: 2023-08-21 20:13 – Updated: 2023-08-21 20:13Summary
The lack of checking of current timestamp allows a LogoutRequest XML to be reused multiple times even when the current time is past the NotOnOrAfter.
Details
It was noticed that in the validatePostRequestAsync() flow in saml.js, the current timestamp is never checked. This could present a vulnerability where a user who has an XML LogoutRequest could validated it if the IssueInstance and the NotOnOrAfter are valid along with valid credentials (signature, certificate etc.).
PoC
I was able to validate a sample valid LogoutRequest XML multiple times through postman by sending it to my endpoint regardless if the current present time was past the NotOnOrAfter time. After some further testing, it seems that only the IssueInstance is checked against NotOnOrAfter. Not sure if this was the intended behaviour but I believe having a never expiring valid LogoutRequest could be dangerous.
Impact
This could impact the user where they would be logged out from an expired LogoutRequest. In bigger contexts, if LogoutRequests are sent out in mass to different SPs, this could impact many users on a large scale.
{
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "@node-saml/node-saml"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.0.5"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2023-40178"
],
"database_specific": {
"cwe_ids": [
"CWE-347",
"CWE-613"
],
"github_reviewed": true,
"github_reviewed_at": "2023-08-21T20:13:05Z",
"nvd_published_at": "2023-08-23T21:15:08Z",
"severity": "MODERATE"
},
"details": "### Summary\n\nThe lack of checking of current timestamp allows a LogoutRequest XML to be reused multiple times even when the current time is past the NotOnOrAfter. \n\n### Details\n\nIt was noticed that in the validatePostRequestAsync() flow in saml.js, the current timestamp is never checked. This could present a vulnerability where a user who has an XML LogoutRequest could validated it if the IssueInstance and the NotOnOrAfter are valid along with valid credentials (signature, certificate etc.). \n\n### PoC\n\nI was able to validate a sample valid LogoutRequest XML multiple times through postman by sending it to my endpoint regardless if the current present time was past the NotOnOrAfter time. After some further testing, it seems that only the IssueInstance is checked against NotOnOrAfter. Not sure if this was the intended behaviour but I believe having a never expiring valid LogoutRequest could be dangerous.\n\n### Impact\n\nThis could impact the user where they would be logged out from an expired LogoutRequest. In bigger contexts, if LogoutRequests are sent out in mass to different SPs, this could impact many users on a large scale.\n",
"id": "GHSA-vx8m-6fhw-pccw",
"modified": "2023-08-21T20:13:05Z",
"published": "2023-08-21T20:13:05Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/node-saml/node-saml/security/advisories/GHSA-vx8m-6fhw-pccw"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40178"
},
{
"type": "WEB",
"url": "https://github.com/node-saml/node-saml/commit/045e3b9c54211fdb95f96edf363679845b195cec"
},
{
"type": "PACKAGE",
"url": "https://github.com/node-saml/node-saml"
},
{
"type": "WEB",
"url": "https://github.com/node-saml/node-saml/releases/tag/v4.0.5"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"type": "CVSS_V3"
}
],
"summary": "@node-saml/node-saml\u0027s validatePostRequestAsync does not include checkTimestampsValidityError"
}
GHSA-VXMM-5M8G-5P2C
Vulnerability from github – Published: 2023-08-09 00:31 – Updated: 2024-04-04 06:43Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via local access.
{
"affected": [],
"aliases": [
"CVE-2023-39211"
],
"database_specific": {
"cwe_ids": [
"CWE-269",
"CWE-347"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-08-08T22:15:10Z",
"severity": "HIGH"
},
"details": "Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via local access.",
"id": "GHSA-vxmm-5m8g-5p2c",
"modified": "2024-04-04T06:43:10Z",
"published": "2023-08-09T00:31:56Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39211"
},
{
"type": "WEB",
"url": "https://explore.zoom.us/en/trust/security/security-bulletin"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-W257-36FH-JMR6
Vulnerability from github – Published: 2026-07-27 21:31 – Updated: 2026-07-27 21:31Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token.
{
"affected": [],
"aliases": [
"CVE-2026-65616"
],
"database_specific": {
"cwe_ids": [
"CWE-347"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-07-27T20:16:40Z",
"severity": "HIGH"
},
"details": "Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token.",
"id": "GHSA-w257-36fh-jmr6",
"modified": "2026-07-27T21:31:22Z",
"published": "2026-07-27T21:31:22Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65616"
},
{
"type": "WEB",
"url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases"
},
{
"type": "WEB",
"url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-W2CX-738M-MC7W
Vulnerability from github – Published: 2026-09-29 23:16 – Updated: 2026-09-29 23:16Summary
PyJWT 2.13.0 contains an incomplete defense against algorithm confusion when
an application mixes symmetric and asymmetric algorithms in one verification
path. A public RSA, EC, or OKP JWK can be accepted as an HMAC secret when it
is wrapped in a JWKS object, nested in an array, or represented in another
container form that does not expose a top-level kty member.
Impact
An attacker who knows the public key material can forge HS256/HS384/HS512 tokens if the application simultaneously:
- allows both HS* and asymmetric algorithms;
- passes raw public JWK/JWKS JSON as
key=; and - uses that same value as the HMAC secret.
This can allow forged JWT claims in affected application configurations. The issue does not affect applications that keep symmetric and asymmetric verification paths separate and follow PyJWT's algorithm-selection guidance.
Fix status
The fix is on master in commit 801cd12 (fix: reject public JWK container
HMAC keys). HMACAlgorithm.prepare_key now rejects public JWK members found in
objects, arrays, nested containers, BOM/UTF variants, and recursion-limit
inputs. It also recognizes escaped JSON member names without treating ordinary
string values as JWKs. Ordinary JSON secrets remain accepted byte-for-byte.
The change was tested with focused regression tests and the full local tox matrix. Available Python 3.9, 3.12, and 3.13 crypto/no-crypto suites, mypy, package metadata, and coverage passed; unavailable interpreters were skipped by the project configuration. A fresh independent Astra/max security review accepted the final diff with no blocking findings.
The affected range is = 2.13.0. The fix is on the unreleased development
branch; the patched version will be recorded when a released 2.x version
containing the fix is available. This advisory is being moved to draft pending
that release.
Reporter credit
Credit: Charles Vosburgh / Trilobyte.
Original report
The original report and reproduction package are retained in the private advisory record.
Maintainer update — 2026-09-11
The verified fix for this advisory is included in PyJWT 2.14.0, released on 2026-09-11 and available on PyPI. PyJWT 2.14.0 is the first release containing the fix. This advisory is now published with 2.14.0 recorded as the patched version.
{
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "PyJWT"
},
"ranges": [
{
"events": [
{
"introduced": "2.13.0"
},
{
"fixed": "2.14.0"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"2.13.0"
]
}
],
"aliases": [
"CVE-2026-102273"
],
"database_specific": {
"cwe_ids": [
"CWE-347"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-29T23:16:55Z",
"nvd_published_at": "2026-09-28T21:17:15Z",
"severity": "HIGH"
},
"details": "### Summary\n\nPyJWT 2.13.0 contains an incomplete defense against algorithm confusion when\nan application mixes symmetric and asymmetric algorithms in one verification\npath. A public RSA, EC, or OKP JWK can be accepted as an HMAC secret when it\nis wrapped in a JWKS object, nested in an array, or represented in another\ncontainer form that does not expose a top-level `kty` member.\n\n### Impact\n\nAn attacker who knows the public key material can forge HS256/HS384/HS512\ntokens if the application simultaneously:\n\n* allows both HS* and asymmetric algorithms;\n* passes raw public JWK/JWKS JSON as `key=`; and\n* uses that same value as the HMAC secret.\n\nThis can allow forged JWT claims in affected application configurations. The\nissue does not affect applications that keep symmetric and asymmetric\nverification paths separate and follow PyJWT\u0027s algorithm-selection guidance.\n\n### Fix status\n\nThe fix is on `master` in commit `801cd12` (`fix: reject public JWK container\nHMAC keys`). `HMACAlgorithm.prepare_key` now rejects public JWK members found in\nobjects, arrays, nested containers, BOM/UTF variants, and recursion-limit\ninputs. It also recognizes escaped JSON member names without treating ordinary\nstring values as JWKs. Ordinary JSON secrets remain accepted byte-for-byte.\n\nThe change was tested with focused regression tests and the full local tox\nmatrix. Available Python 3.9, 3.12, and 3.13 crypto/no-crypto suites, mypy,\npackage metadata, and coverage passed; unavailable interpreters were skipped\nby the project configuration. A fresh independent Astra/max security review\naccepted the final diff with no blocking findings.\n\nThe affected range is `= 2.13.0`. The fix is on the unreleased development\nbranch; the patched version will be recorded when a released 2.x version\ncontaining the fix is available. This advisory is being moved to draft pending\nthat release.\n\n### Reporter credit\n\nCredit: Charles Vosburgh / Trilobyte.\n\n### Original report\n\nThe original report and reproduction package are retained in the private\nadvisory record.\n\n## Maintainer update \u2014 2026-09-11\n\nThe verified fix for this advisory is included in PyJWT 2.14.0, released on 2026-09-11 and available on PyPI. PyJWT 2.14.0 is the first release containing the fix. This advisory is now published with 2.14.0 recorded as the patched version.",
"id": "GHSA-w2cx-738m-mc7w",
"modified": "2026-09-29T23:16:55Z",
"published": "2026-09-29T23:16:55Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w2cx-738m-mc7w"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-102273"
},
{
"type": "WEB",
"url": "https://github.com/jpadilla/pyjwt/commit/801cd128528c62d9b23fcd161d1a2e1c17982f95"
},
{
"type": "PACKAGE",
"url": "https://github.com/jpadilla/pyjwt"
},
{
"type": "WEB",
"url": "https://github.com/jpadilla/pyjwt/releases/tag/2.14.0"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "PyJWT accepts public JWK containers as HMAC secrets"
}
No mitigation information available for this CWE.
CAPEC-463: Padding Oracle Crypto Attack
An adversary is able to efficiently decrypt data without knowing the decryption key if a target system leaks data on whether or not a padding error happened while decrypting the ciphertext. A target system that leaks this type of information becomes the padding oracle and an adversary is able to make use of that oracle to efficiently decrypt data without knowing the decryption key by issuing on average 128*b calls to the padding oracle (where b is the number of bytes in the ciphertext block). In addition to performing decryption, an adversary is also able to produce valid ciphertexts (i.e., perform encryption) by using the padding oracle, all without knowing the encryption key.
CAPEC-475: Signature Spoofing by Improper Validation
An adversary exploits a cryptographic weakness in the signature verification algorithm implementation to generate a valid signature without knowing the key.