8.1
CVSSv3

CVE-2016-10563

Published: 31/05/2018 Updated: 09/10/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

During the installation process, the go-ipfs-deps module prior to 0.4.4 insecurely downloads resources over HTTP. This allows for a MITM attack to compromise the integrity of the resources used by this module and could allow for further compromise.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ipfs go-ipfs-dep