Vulnerabilities/

Denial of Service in ipfs-bitswap

Severity:
Medium

Description

Versions of ipfs-bitswap prior to 0.24.1 are vulnerable to Denial of Service (DoS). The package put unwanted blocks in the blockstore, which could be used to exhaust system resources in specific conditions.

Recommendation

Update the ipfs-bitswap package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
ipfs-bitswap
Anything's wrong? Let us know Last updated on December 07, 2023

This issue is available in SmartScanner Professional

See Pricing