First published: Thu Apr 26 2018(Updated: )
During the installation process, the go-ipfs-deps module before 0.4.4 insecurely downloads resources over HTTP. This allows for a MITM attack to compromise the integrity of the resources used by this module and could allow for further compromise.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
go-ipfs | <0.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10563 has been classified as a moderate severity vulnerability due to the potential for MITM attacks.
To fix CVE-2016-10563, upgrade the go-ipfs-deps module to version 0.4.4 or later.
CVE-2016-10563 affects the go-ipfs-deps module used with Node.js prior to version 0.4.4.
CVE-2016-10563 allows for a man-in-the-middle (MITM) attack that can compromise the integrity of downloaded resources.
As of now, there is no publicly known exploit for CVE-2016-10563, but the vulnerability itself presents a significant risk.