Vulnerability Description
During the installation process, the go-ipfs-deps module before 0.4.4 insecurely downloads resources over HTTP. This allows for a MITM attack to compromise the integrity of the resources used by this module and could allow for further compromise.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ipfs | Go-Ipfs-Dep | < 0.4.4 |
Related Weaknesses (CWE)
References
- https://github.com/diasdavid/go-ipfs-dep/pull/12Issue TrackingThird Party Advisory
- https://nodesecurity.io/advisories/156Third Party Advisory
- https://github.com/diasdavid/go-ipfs-dep/pull/12Issue TrackingThird Party Advisory
- https://nodesecurity.io/advisories/156Third Party Advisory
FAQ
What is CVE-2016-10563?
CVE-2016-10563 is a vulnerability with a CVSS score of 8.1 (HIGH). During the installation process, the go-ipfs-deps module before 0.4.4 insecurely downloads resources over HTTP. This allows for a MITM attack to compromise the integrity of the resources used by this ...
How severe is CVE-2016-10563?
CVE-2016-10563 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-10563?
Check the references section above for vendor advisories and patch information. Affected products include: Ipfs Go-Ipfs-Dep.