Information Exposure Affecting github.com/keybase/client/go/libkb Open this link in a new tab package, versions <5.8.0


0.0
low
  • Attack Complexity

    High

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • snyk-id

    SNYK-GOLANG-GITHUBCOMKEYBASECLIENTGOLIBKB-1920671

  • published

    12 Nov 2021

  • disclosed

    12 Nov 2021

  • credit

    Olivia O'Hara, John Jackson, Jackson Henry, Robert Willis

How to fix?

Upgrade github.com/keybase/client/go/libkb to version 5.8.0 or higher.

Overview

github.com/keybase/client/go/libkb is a code used in populating JSON objects to generating Keybase-style signatures.

Affected versions of this package are vulnerable to Information Exposure via exploded messages initiated by a user. If the receiving user places the chat session in the background while the sending user explodes the messages, this could lead to disclosure of sensitive information.

This vulnerability is relevant for Keybase Client for Android and iOS.