Failure to validate signature during handshake
High severity
GitHub Reviewed
Published
Mar 17, 2022
in
ChainSafe/js-libp2p-noise
•
Updated Jan 27, 2023
Package
Affected versions
< 4.1.2
>= 5.0.0, < 5.0.3
Patched versions
4.1.2
5.0.3
Description
Published by the National Vulnerability Database
Mar 17, 2022
Published to the GitHub Advisory Database
Mar 18, 2022
Reviewed
Mar 18, 2022
Last updated
Jan 27, 2023
Impact
@chainsafe/libp2p-noise
before 4.1.2 and 5.0.3 was not correctly validating signatures during the handshake process.This may allow a man-in-the-middle to pose as other peers and get those peers banned.
Patches
Users should upgrade to 4.1.2 or 5.0.3
Workarounds
No workarounds, just patch upgrade
References
ChainSafe/js-libp2p-noise#130
References