Information Exposure Affecting github.com/keybase/client/go/libkb Open this link in a new tab package, versions <5.8.0
Attack Complexity
High
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications-
snyk-id
SNYK-GOLANG-GITHUBCOMKEYBASECLIENTGOLIBKB-1920671
-
published
12 Nov 2021
-
disclosed
12 Nov 2021
-
credit
Olivia O'Hara, John Jackson, Jackson Henry, Robert Willis
Introduced: 12 Nov 2021
CVE-2021-34421 Open this link in a new tabHow to fix?
Upgrade github.com/keybase/client/go/libkb
to version 5.8.0 or higher.
Overview
github.com/keybase/client/go/libkb is a code used in populating JSON objects to generating Keybase-style signatures.
Affected versions of this package are vulnerable to Information Exposure via exploded messages initiated by a user. If the receiving user places the chat session in the background while the sending user explodes the messages, this could lead to disclosure of sensitive information.
This vulnerability is relevant for Keybase Client
for Android and iOS.