GHSA-j59f-6m4q-62h6

Suggest an improvement
Source
https://github.com/advisories/GHSA-j59f-6m4q-62h6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/05/GHSA-j59f-6m4q-62h6/GHSA-j59f-6m4q-62h6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-j59f-6m4q-62h6
Published
2019-05-30T17:28:48Z
Modified
2023-12-07T22:05:54Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Improper Key Verification in ipns
Details

Versions 0.1.1 or 0.1.2 of ipns are vulnerable to improper key validation. This is due to the public key verification was not being performed properly, resulting in any key being valid.

Recommendation

Update to version 0.1.3 or later.

Database specific
{
    "cwe_ids":  [
        "CWE-287"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2019-05-30T17:28:19Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / ipns

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.1.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/05/GHSA-j59f-6m4q-62h6/GHSA-j59f-6m4q-62h6.json"