CVE-2020-26283
Summary
| CVE | CVE-2020-26283 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-24 21:15:00 UTC |
| Updated | 2021-03-27 01:45:00 UTC |
| Description | go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem. In go-ipfs before version 0.8.0, control characters are not escaped from console output. This can result in hiding input from the user which could result in the user taking an unknown, malicious action. This is fixed in version 0.8.0. |
Risk And Classification
Problem Types: CWE-116
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Escape non-printable characters in user output by gammazero · Pull Request #7831 · ipfs/go-ipfs · GitHub | MISC | github.com | |
| Merge pull request #7831 from ipfs/fix/escape-nonprintable-chars · ipfs/go-ipfs@fb0a9ac · GitHub | MISC | github.com | |
| Control character injection in console output · Advisory · ipfs/go-ipfs · GitHub | CONFIRM | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.