Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wmx6-vxcf-c3gr

Опубликовано: 15 нояб. 2019
Источник: github
Github: Прошло ревью
CVSS3: 5.7

Описание

Validation Bypass in slp-validate

Versions of slp-validate prior to 1.0.1 are vulnerable to a validation bypass. Bitcoin scripts may cause the validation result from slp-validate to differ from the specified SLP consensus. This allows an attacker to create a Bitcoin script that causes a hard-fork from the SLP consensus.

Recommendation

Upgrade to version 1.0.1 or later.

Пакеты

Наименование

slp-validate

npm
Затронутые версииВерсия исправления

= 1.0.0

1.0.1

EPSS

Процентиль: 60%
0.00392
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.7
nvd
около 6 лет назад

A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation result of the slp-validate@1.0.0 npm package. An attacker could create a specially crafted Bitcoin script in order to cause a hard-fork from the SLP consensus. All versions >1.0.0 have been patched.

EPSS

Процентиль: 60%
0.00392
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-20