GMS-2019-131: Identity Spoofing in libp2p-secio
(updated )
Affected versions of libp2p-secio
does not correctly verify that the PeerId
of DstPeer
matches the PeerId
discovered in the crypto handshake, resulting in a high severity identity spoofing vulnerability.
Recommendation
Update to version 0.9.0 or later.
References
Detect and mitigate GMS-2019-131 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →