Improper Verification of Cryptographic Signature Affecting @chainsafe/libp2p-noise package, versions <4.1.2>=5.0.0 <5.0.3


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.1% (43rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-CHAINSAFELIBP2PNOISE-2431146
  • published22 Mar 2022
  • disclosed18 Mar 2022
  • creditUnknown

Introduced: 18 Mar 2022

CVE-2022-24759  (opens in a new tab)
CWE-347  (opens in a new tab)

How to fix?

Upgrade @chainsafe/libp2p-noise to version 4.1.2, 5.0.3 or higher.

Overview

@chainsafe/libp2p-noise is a npm CI

Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature by failing to validate signature during the handshake process.

CVSS Scores

version 3.1