PT-2020-12531 · Simple Ledger Protocol Javascript · Slpjs

Jcramer

·

Published

2020-05-12

·

Updated

2020-05-19

·

CVE-2020-11071

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions slpjs versions prior to 0.27.2
Description The issue allows users to experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet could allow spending of the affected tokens, resulting in the destruction of a user's minting baton.
Recommendations For versions prior to 0.27.2, upgrade to version 0.27.2 to resolve the issue. As a temporary workaround, consider avoiding the use of MINT transaction operations until the upgrade is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11071
GHSA-JC83-CPF9-Q7C6

Affected Products

Slpjs