CRITICAL
False-negative validation results in MINT transactions with invalid baton
Published May 12, 2020
8.6
CRITICALCVSS 3.1
EPSS 0.93%
Description
SLPJS (npm package slpjs) before version 0.27.2, has a vulnerability where users could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet could allow spending of the affected tokens which would result in the destruction of a user's minting baton. This is fixed in version 0.27.2.
Affected products
-
- Version < 0.27.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Simpleledger | Slpjs | n/a |
|
- < 0.27.2
No data.
No Red Hat product state for this CVE.
slpjs
npm
Introduced 0 Fixed 0.27.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | slpjs | 0 | 0.27.2 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://github.com/advisories/GHSA-jc83-cpf9-q7c6 Advisory
- https://github.com/simpleledger/slpjs/commit/3671be2ffb6d4cfa94c00c6dc8649d1ba1d75754 x_refsource_MISCPatchTool Signature
- https://github.com/simpleledger/slpjs/security/advisories/GHSA-jc83-cpf9-q7c6 x_refsource_CONFIRMTool Signature
- https://nvd.nist.gov/vuln/detail/CVE-2020-11071
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-jc83-cpf9-q7c6 | Advisory | |
| https://github.com/simpleledger/slpjs/commit/3671be2ffb6d4cfa94c00c6dc8649d1ba1d75754 | x_refsource_MISCPatchTool Signature | |
| https://github.com/simpleledger/slpjs/security/advisories/GHSA-jc83-cpf9-q7c6 | x_refsource_CONFIRMTool Signature | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-11071 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 12, 2020
Updated Aug 4, 2024
Reserved Mar 30, 2020
Link CVE-2020-11071
CISA Vulnrichment
GHSA-JC83-CPF9-Q7C6 Updated n/a