Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8r76-fr72-j32w

Опубликовано: 12 дек. 2022
Источник: github
Github: Прошло ревью

Описание

Creator Verification Error when Bubblegum Activate

This was an error found by @metamania01 of the Audit Company Solshield.

It allowed one to verify a creator that did not sign by making use of a provision in Token Metadata that allows Creators who have signed compressed nfts to allow them to decompress with verified creators.

The issue is now patched. For more info see. https://twitter.com/thehasheddude/status/1601642138143375360

Пакеты

Наименование

mpl-bubblegum

rust
Затронутые версииВерсия исправления

< 0.6.0

0.6.0

Наименование

mpl-token-metadata

rust
Затронутые версииВерсия исправления

>= 1.5.0, < 1.6.3

1.6.3