PT-2020-12494 · Electron Cash · Electron-Cash-Slp

Jcramer

·

Published

2020-04-28

·

Updated

2020-05-06

·

CVE-2020-11014

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Electron-Cash-SLP versions prior to 3.6.2
Description The issue affects token creators using the "Mint Tool" feature of the Electron Cash SLP Edition, putting them at risk of sending the minting authority baton to the wrong SLP address. This could allow another party to issue new tokens or permanently destroy future minting capability.
Recommendations For versions prior to 3.6.2, update to version 3.6.2 to resolve the issue. As a temporary workaround, consider restricting the use of the "Mint Tool" feature until the update is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-11014
GHSA-CCHM-GRX2-G873

Affected Products

Electron-Cash-Slp