Improper Key Verification in ipns
High severity
GitHub Reviewed
Published
May 30, 2019
to the GitHub Advisory Database
•
Updated Dec 7, 2023
Description
Reviewed
May 30, 2019
Published to the GitHub Advisory Database
May 30, 2019
Last updated
Dec 7, 2023
Versions 0.1.1 or 0.1.2 of
ipns
are vulnerable to improper key validation. This is due to the public key verification was not being performed properly, resulting in any key being valid.Recommendation
Update to version 0.1.3 or later.
References