CVE-2016-10563

Severity CVSS v4.0:
Pending analysis
Type:
CWE-310 Cryptographic Issues
Publication date:
31/05/2018
Last modified:
09/10/2019

Description

During the installation process, the go-ipfs-deps module before 0.4.4 insecurely downloads resources over HTTP. This allows for a MITM attack to compromise the integrity of the resources used by this module and could allow for further compromise.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ipfs:go-ipfs-dep:*:*:*:*:*:node.js:*:* 0.4.4 (excluding)