CVE Database
/

CVE-2016-10563

Back to search

CVE-2016-10563

Published: May 31, 2018

Modified: Sep 16, 2024

PUBLISHED

Description

During the installation process, the go-ipfs-deps module before 0.4.4 insecurely downloads resources over HTTP. This allows for a MITM attack to compromise the integrity of the resources used by this module and could allow for further compromise.

VendorProductVersions

HackerOne

go-ipfs-dep node module

affected
<0.4.4

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now