HIGH7.5
GHSA-4q4x-67hx-5mpg
Failure to properly verify ed25519 signatures in libp2p-core
Details
Affected versions of this crate did not properly verify ed25519 signatures. Any signature with a correct length was considered valid. This allows an attacker to impersonate any node identity.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/libp2p-core
Introduced in:
0Fixed in: 0.8.1Upgrade libp2p-core to 0.8.1 or newer (ecosystem crates.io).