CVE-2022-24759
17.03.2022, 17:15
`@chainsafe/libp2p-noise` contains TypeScript implementation of noise protocol, an encryption protocol used in libp2p. `@chainsafe/libp2p-noise` before 4.1.2 and 5.0.3 does not correctly validate signatures during the handshake process. This may allow a man-in-the-middle to pose as other peers and get those peers banned. Users should upgrade to version 4.1.2 or 5.0.3 to receive a patch. There are currently no known workarounds.Enginsight
Vendor | Product | Version |
---|---|---|
chainsafe | js-libp2p-noise | 𝑥 < 4.1.2 |
chainsafe | js-libp2p-noise | 5.0.0 ≤ 𝑥 < 5.0.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References