Chainsafe · @Chainsafe/Libp2P-Noise · CVE-2022-24759
**Name of the Vulnerable Software and Affected Versions**
@chainsafe/libp2p-noise versions prior to 4.1.2
@chainsafe/libp2p-noise versions prior to 5.0.3
**Description**
The issue is related to the incorrect validation of signatures during the handshake process in the noise protocol implementation. This may allow a man-in-the-middle to pose as other peers and get those peers banned.
**Recommendations**
For versions prior to 4.1.2, upgrade to version 4.1.2 to receive a patch.
For versions prior to 5.0.3, upgrade to version 5.0.3 to receive a patch.
As a temporary workaround, consider restricting access to the handshake process until a patch is available.