Compliance Node Overview
MITRE CAPEC-461 (Web Services API Signature Forgery Leveraging Hash Function Extension Weakness) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary utilizes a hash function extension/padding weakness, to modify the parameters passed to the web service requesting authentication by generating their own call in order to generate a legitimate signature hash (as described in the notes), without knowledge of the secret token sometimes provided by the web service. Likelihood of attack: Unknown. Typical severity: High. Maps to weaknesses CWE-328, CWE-290.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/461.html
SHA-256 integrity: 6d6aba0c85c6fd2a466be679a90745654dbf61cc0d5af0fd7720e28f13043583
Primary Citations — 8 traced to source
- MITRE CAPEC-461: Web Services API Signature Forgery Leveraging Hash Function Extension Weakness (https://capec.mitre.org/data/definitions/461.html)
- CWE-328: underlying weakness (http://cwe.mitre.org/data/definitions/328.html)
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.