PT-2020-21433 · Vp Toolkit · Vp-Toolkit

Published

2020-03-06

·

Updated

2020-03-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions vp-toolkit versions prior to 0.2.2
Description The verifyVerifiableCredential() method does not check if the credential.issuer DID matches the signer of the credential, which impacts the verifier.
Recommendations For versions prior to 0.2.2, update to version 0.2.2 to resolve the issue. As a temporary workaround, consider trusting the issuer's public key from the credential.proof.verificationMethod field for certain credentials if you trust certain issuers as a verifier.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GHSA-P94W-42G3-F7H4

Affected Products

Vp-Toolkit