CVE-2019-15545: Failure to properly verify ed25519 signatures in libp2p-core
(updated )
Affected versions of this crate did not properly verify ed25519 signatures. Any signature with a correct length was considered valid. This allows an attacker to impersonate any node identity.
References
Detect and mitigate CVE-2019-15545 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →