Impact
@chainsafe/libp2p-noise
before 4.1.2 and 5.0.3 was not correctly validating signatures during the handshake process.
This may allow a man-in-the-middle to pose as other peers and get those peers banned.
Patches
Users should upgrade to 4.1.2 or 5.0.3
Workarounds
No workarounds, just patch upgrade
References
#130
Impact
@chainsafe/libp2p-noise
before 4.1.2 and 5.0.3 was not correctly validating signatures during the handshake process.This may allow a man-in-the-middle to pose as other peers and get those peers banned.
Patches
Users should upgrade to 4.1.2 or 5.0.3
Workarounds
No workarounds, just patch upgrade
References
#130