CRITICAL
False-negative validation results in MINT transactions with invalid baton
Published May 12, 2020
8.6
CRITICALCVSS 3.1
EPSS 1.04%
Description
In SLP Validate (npm package slp-validate) before version 1.2.1, users could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet could allow spending of the affected tokens which would result in the destruction of a user's minting baton. This has been fixed in slp-validate in version 1.2.1. Additonally, slpjs version 0.27.2 has a related fix under related CVE-2020-11071.
Affected products
-
- Version < 1.2.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Simpleledger | Slp-Validate | n/a |
|
- < 1.2.1
No data.
No Red Hat product state for this CVE.
slp-validate
npm
Introduced 0 Fixed 1.2.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | slp-validate | 0 | 1.2.1 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://github.com/advisories/GHSA-4w97-57v2-3w44 Advisory
- https://github.com/simpleledger/slp-validate.js/security/advisories/GHSA-4w97-57v2-3w44
- https://github.com/simpleledger/slp-validate/commit/cde95c0c6470dceb4f023cd462f904135ebd73e7 x_refsource_MISCPatchThird Party Advisory
- https://github.com/simpleledger/slp-validate/security/advisories/GHSA-4w97-57v2-3w44 x_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-11072
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-4w97-57v2-3w44 | Advisory | |
| https://github.com/simpleledger/slp-validate.js/security/advisories/GHSA-4w97-57v2-3w44 | ||
| https://github.com/simpleledger/slp-validate/commit/cde95c0c6470dceb4f023cd462f904135ebd73e7 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/simpleledger/slp-validate/security/advisories/GHSA-4w97-57v2-3w44 | x_refsource_CONFIRMThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-11072 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 12, 2020
Updated Aug 4, 2024
Reserved Mar 30, 2020
Link CVE-2020-11072
CISA Vulnrichment
GHSA-4W97-57V2-3W44 Updated n/a