PT-2022-28223 · Crates.Io · Mpl-Bubblegum+1

Published

2022-12-12

·

Updated

2022-12-12

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions No specific software or versions mentioned.
Description The issue allowed verification of a creator that did not sign by utilizing a provision in Token Metadata. This provision enables creators who have signed compressed NFTs to decompress them with verified creators. The issue has been patched.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

GHSA-8R76-FR72-J32W

Affected Products

Mpl-Bubblegum
Mpl-Token-Metadata