@chainsafe/libp2p-noise before 4.1.2 and 5.0.3 was not correctly validating signatures during the handshake process.
This may allow a man-in-the-middle to pose as other peers and get those peers banned.
Users should upgrade to 4.1.2 or 5.0.3
No workarounds, just patch upgrade
{
"cwe_ids": [
"CWE-347"
],
"github_reviewed": true,
"github_reviewed_at": "2022-03-18T18:57:53Z",
"nvd_published_at": "2022-03-17T17:15:00Z",
"severity": "HIGH"
}