Versions of ipfs-bitswap
prior to 0.24.1 are vulnerable to Denial of Service (DoS). The package put unwanted blocks in the blockstore, which could be used to exhaust system resources in specific conditions.
Upgrade to version 0.24.1 or later.
{ "nvd_published_at": null, "severity": "MODERATE", "github_reviewed": true, "cwe_ids": [ "CWE-400" ], "github_reviewed_at": "2020-08-31T18:40:27Z" }