Vulnerabilities
Vulnerable Software
Protocol:  Security Vulnerabilities
go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem. In go-ipfs before version 0.8.0, control characters are not escaped from console output. This can result in hiding input from the user which could result in the user taking an unknown, malicious action. This is fixed in version 0.8.0.
CVSS Score
6.8
EPSS Score
0.015
Published
2021-03-24
An issue was discovered in the multihash crate before 0.11.3 for Rust. The from_slice parsing code can panic via unsanitized data from a network server.
CVSS Score
7.5
EPSS Score
0.014
Published
2020-12-31
An issue was discovered in IPFS (aka go-ipfs) 0.4.23. An attacker can generate ephemeral identities (Sybils) and leverage the IPFS connection management reputation system to poison other nodes' routing tables, eclipsing the nodes that are the target of the attack from the rest of the network. Later versions, in particular go-ipfs 0.7, mitigate this.
CVSS Score
7.5
EPSS Score
0.012
Published
2020-11-02
Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.
CVSS Score
9.8
EPSS Score
0.019
Published
2020-07-07


Contact Us

Shodan ® - All rights reserved