CVE-2020-10937
Last modified
CVE-2020-10937 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An issue was discovered in IPFS (aka go-ipfs) 0.4.23. An attacker can generate ephemeral identities (Sybils) and leverage the IPFS connection management reputation system to poison other nodes' routing tables, eclipsing the nodes that are the target of the attack from the rest of the network. EPSS estimates a 1.15% chance of exploitation in the next 30 days.
Description
An issue was discovered in IPFS (aka go-ipfs) 0.4.23. An attacker can generate ephemeral identities (Sybils) and leverage the IPFS connection management reputation system to poison other nodes' routing tables, eclipsing the nodes that are the target of the attack from the rest of the network. Later versions, in particular go-ipfs 0.7, mitigate this.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Protocol | Ipfs | 0.4.23 |
References
- https://blog.ipfs.io/2020-10-30-dht-hardening/Vendor Advisory
- https://blog.ipfs.io/2020-10-30-dht-hardening/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-10937?
How severe is CVE-2020-10937?
How do I fix CVE-2020-10937?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-10931Memcached 1.6.x before 1.6.2 allows remote attackers to caus…7.5
- CVE-2020-10932An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.…4.7
- CVE-2020-10933An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x t…5.3
- CVE-2020-10934Acyba AcyMailing before 6.9.2 mishandles file uploads by adm…7.2
- CVE-2020-10935Zulip Server before 2.1.3 allows XSS via a Markdown link, wi…5.4
- CVE-2020-10936Sympa before 6.2.56 allows privilege escalation.7.8
- CVE-2020-10938GraphicsMagick before 1.3.35 has an integer overflow and res…9.8
- CVE-2020-10939Insecure, default path permissions in PHOENIX CONTACT PC WOR…7.8
- CVE-2020-1094An elevation of privilege vulnerability exists when the Wind…7.8
- CVE-2020-10940Local Privilege Escalation can occur in PHOENIX CONTACT PORT…7.8
- CVE-2020-10941Arm Mbed TLS before 2.16.5 allows attackers to obtain sensit…5.9
- CVE-2020-10942In the Linux kernel before 5.5.8, get_raw_socket in drivers/…5.3
Are you affected by CVE-2020-10937?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
