Vulnerabilities/

Improper Key Verification in ipns

Severity:
High

Description

Versions 0.1.1 or 0.1.2 of ipns are vulnerable to improper key validation. This is due to the public key verification was not being performed properly, resulting in any key being valid.

Recommendation

Update the ipns package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
ipns
Anything's wrong? Let us know Last updated on December 07, 2023

This issue is available in SmartScanner Professional

See Pricing