CVE-2020-26283 Information

Description

go-ipfs is an open-source golang implementation of IPFS which is a global versioned peer-to-peer filesystem. In go-ipfs before version 0.8.0 control characters are not escaped from console output. This can result in hiding input from the user which could result in the user taking an unknown malicious action. This is fixed in version 0.8.0.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Reference

https://github.com/ipfs/go-ipfs/security/advisories/GHSA-r4gv-vj59-cccm https://github.com/ipfs/go-ipfs/commit/fb0a9acd2d8288bd1028c3219a420de62a09683a https://github.com/ipfs/go-ipfs/pull/7831

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

8.8

Share on: