Vulnerabilities/

Failure to validate signature during handshake

Severity:
High

Description

@chainsafe/libp2p-noise before 4.1.2 and 5.0.3 was not correctly validating signatures during the handshake process. This may allow a man-in-the-middle to pose as other peers and get those peers banned.

Recommendation

Update the @chainsafe/libp2p-noise package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@chainsafe/libp2p-noise
Anything's wrong? Let us know Last updated on January 27, 2023

This issue is available in SmartScanner Professional

See Pricing