Skip to content

False-negative validation results in MINT transactions with invalid baton

Critical
jcramer published GHSA-4w97-57v2-3w44 May 11, 2020

Package

npm slp-validate (npm)

Affected versions

<1.2.1

Patched versions

1.2.1

Description

Impact

Users could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet could allow spending of the affected tokens which would result in the destruction of a user's minting baton.

Patches

npm package slp-validate has been patched and published as version 1.2.1.

Workarounds

Upgrade to slp-validate 1.2.1.

References

For more information

If you have any questions or comments about this advisory:

Severity

Critical

CVE ID

CVE-2020-11072

Weaknesses

No CWEs