Skip to content

Failure to validate signature during handshake

High
wemeetagain published GHSA-j3ff-xp6c-6gcc Mar 17, 2022

Package

npm @chainsafe/libp2p-noise (npm)

Affected versions

<4.1.2,>4.1.2,<5.0.3

Patched versions

4.1.2,5.0.3

Description

Impact

@chainsafe/libp2p-noise before 4.1.2 and 5.0.3 was not correctly validating signatures during the handshake process.
This may allow a man-in-the-middle to pose as other peers and get those peers banned.

Patches

Users should upgrade to 4.1.2 or 5.0.3

Workarounds

No workarounds, just patch upgrade

References

#130

Severity

High

CVE ID

CVE-2022-24759

Weaknesses

No CWEs