CVE-2020-26283 Information
Jun 07, 2022
cve
Description
go-ipfs is an open-source golang implementation of IPFS which is a global versioned peer-to-peer filesystem. In go-ipfs before version 0.8.0 control characters are not escaped from console output. This can result in hiding input from the user which could result in the user taking an unknown malicious action. This is fixed in version 0.8.0.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://github.com/ipfs/go-ipfs/security/advisories/GHSA-r4gv-vj59-cccm https://github.com/ipfs/go-ipfs/commit/fb0a9acd2d8288bd1028c3219a420de62a09683a https://github.com/ipfs/go-ipfs/pull/7831
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: