Denial of Service in ipfs-bitswap
Moderate severity
GitHub Reviewed
Published
Sep 2, 2020
to the GitHub Advisory Database
•
Updated Dec 7, 2023
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 2, 2020
Last updated
Dec 7, 2023
Versions of
ipfs-bitswap
prior to 0.24.1 are vulnerable to Denial of Service (DoS). The package put unwanted blocks in the blockstore, which could be used to exhaust system resources in specific conditions.Recommendation
Upgrade to version 0.24.1 or later.
References