Description
Versions 0.1.1 or 0.1.2 of ipns are vulnerable to improper key validation. This is due to the public key verification was not being performed properly, resulting in any key being valid.
Recommendation
Update the ipns package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.1.3
- Patched version(s): 0.1.3
References
Related Issues
- Improper Key Verification in openpgp - CVE-2019-9154
- Improper Verification of Cryptographic Signature in aws-encryption-sdk-javascript - Vulnerability
- Axios: Deep formToJSON Key Recursion Can Cause Denial of Service - Vulnerability
- @nfid/embed has compromised private key due to @dfinity/auth-client producing insecure session keys - Vulnerability
You might also like:
- Tags:
- npm
- ipns
Anything's wrong? Let us know Last updated on December 07, 2023


