SCA: security update for github.com/ipfs/go-libipfs (GHSA-m974-xj4j-7qv5)

high Tenable Cloud Security Plugin ID 416866

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Boxo, formerly known as go-libipfs, is a library for building IPFS applications and implementations. In
versions 0.4.0 and 0.5.0, if an attacker is able allocate arbitrary many bytes in the Bitswap server,
those allocations are lasting even if the connection is closed. This affects users accepting untrusted
connections with the Bitswap server and also affects users using the old API stubs at `github.com/ipfs/go-
libipfs/bitswap` because users then transitively import `github.com/ipfs/go-libipfs/bitswap/server`. Boxo
versions 0.6.0 and 0.4.1 contain a patch for this issue. As a workaround, those who are using the stub
object at `github.com/ipfs/go-libipfs/bitswap` not taking advantage of the features provided by the server
can refactor their code to use the new split API that will allow them to run in a client only mode:
`github.com/ipfs/go-libipfs/bitswap/client`. (CVE-2023-25568)

See Also

https://github.com/advisories/GHSA-m974-xj4j-7qv5

Plugin Details

Severity: High

ID: 416866

Version: Revision 1.8

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 94.66

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2023-25568

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/11/2023

Vulnerability Publication Date: 5/10/2023

Reference Information

CVE: CVE-2023-25568