Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4w97-57v2-3w44

Опубликовано: 12 мая 2020
Источник: github
Github: Прошло ревью
CVSS3: 8.6

Описание

False-negative validation results in MINT transactions with invalid baton

Impact

Users could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet could allow spending of the affected tokens which would result in the destruction of a user's minting baton.

Patches

npm package slp-validate has been patched and published as version 1.2.1.

Workarounds

Upgrade to slp-validate 1.2.1.

References

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

slp-validate

npm
Затронутые версииВерсия исправления

< 1.2.1

1.2.1

EPSS

Процентиль: 46%
0.00237
Низкий

8.6 High

CVSS3

Дефекты

CWE-697

Связанные уязвимости

CVSS3: 8.6
nvd
больше 5 лет назад

In SLP Validate (npm package slp-validate) before version 1.2.1, users could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet could allow spending of the affected tokens which would result in the destruction of a user's minting baton. This has been fixed in slp-validate in version 1.2.1. Additonally, slpjs version 0.27.2 has a related fix under related CVE-2020-11071.

EPSS

Процентиль: 46%
0.00237
Низкий

8.6 High

CVSS3

Дефекты

CWE-697