CVE-2022-24759

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/03/2022
Last modified:
23/03/2022

Description

`@chainsafe/libp2p-noise` contains TypeScript implementation of noise protocol, an encryption protocol used in libp2p. `@chainsafe/libp2p-noise` before 4.1.2 and 5.0.3 does not correctly validate signatures during the handshake process. This may allow a man-in-the-middle to pose as other peers and get those peers banned. Users should upgrade to version 4.1.2 or 5.0.3 to receive a patch. There are currently no known workarounds.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:chainsafe:js-libp2p-noise:*:*:*:*:*:node.js:*:* 4.1.2 (excluding)
cpe:2.3:a:chainsafe:js-libp2p-noise:*:*:*:*:*:node.js:*:* 5.0.0 (including) 5.0.3 (excluding)