GHSA-wp4m-7hpj-8qp8
Dashboard / Vulnerabilities / GHSA-wp4m-7hpj-8qp8
GHSA-wp4m-7hpj-8qp8
Summary: Duplicate Advisory: Discovery uses the same AES/GCM Nonce throughout the session
Details: ### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-w3hj-wr2q-x83g. This link is maintained to preserve external references. ### Original Description Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. which should ideally be unique for every message. The node's private key isn't compromised, only the session key generated for specific peer communication is exposed.
References: https://github.com/ConsenSys/discovery/security/advisories/GHSA-w3hj-wr2q-x83g, https://nvd.nist.gov/vuln/detail/CVE-2024-23688, https://github.com/advisories/GHSA-w3hj-wr2q-x83g, https://vulncheck.com/advisories/vc-advisory-GHSA-w3hj-wr2q-x83g
Affected packages
Package
Name: tech.pegasys.discovery:discovery
Purl: pkg:maven/tech.pegasys.discovery/discovery
Affected ranges
Type: ECOSYSTEM
Events:
