Information Exposure Affecting github.com/keybase/client/go/libkb package, versions <5.8.0


Severity

Recommended
0.0
low
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.06% (29th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMKEYBASECLIENTGOLIBKB-1920671
  • published12 Nov 2021
  • disclosed12 Nov 2021
  • creditOlivia O'Hara, John Jackson, Jackson Henry, Robert Willis

Introduced: 12 Nov 2021

CVE-2021-34421  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade github.com/keybase/client/go/libkb to version 5.8.0 or higher.

Overview

github.com/keybase/client/go/libkb is a code used in populating JSON objects to generating Keybase-style signatures.

Affected versions of this package are vulnerable to Information Exposure via exploded messages initiated by a user. If the receiving user places the chat session in the background while the sending user explodes the messages, this could lead to disclosure of sensitive information.

This vulnerability is relevant for Keybase Client for Android and iOS.

CVSS Scores

version 3.1