Description
During the installation process, the go-ipfs-deps module before 0.4.4 insecurely downloads resources over HTTP. This allows for a MITM attack to compromise the integrity of the resources used by this module and could allow for further compromise.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0287 | During the installation process, the go-ipfs-deps module before 0.4.4 insecurely downloads resources over HTTP. This allows for a MITM attack to compromise the integrity of the resources used by this module and could allow for further compromise. |
Github GHSA |
GHSA-g3xp-v2ff-x5c3 | Downloads Resources over HTTP in go-ipfs-dep |
References
History
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-09-16T18:49:48.687Z
Reserved: 2017-10-29T00:00:00.000Z
Link: CVE-2016-10563
No data.
Status : Modified
Published: 2018-05-31T20:29:02.283
Modified: 2024-11-21T02:44:17.060
Link: CVE-2016-10563
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA