In SLP Validate (npm package slp-validate) before version 1.2.1, users could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet could allow spending of the affected tokens which would result in the destruction of a user's minting baton. This has been fixed in slp-validate in version 1.2.1. Additonally, slpjs version 0.27.2 has a related fix under related CVE-2020-11071.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-0410 In SLP Validate (npm package slp-validate) before version 1.2.1, users could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet could allow spending of the affected tokens which would result in the destruction of a user's minting baton. This has been fixed in slp-validate in version 1.2.1. Additonally, slpjs version 0.27.2 has a related fix under related CVE-2020-11071.
Github GHSA Github GHSA GHSA-4w97-57v2-3w44 False-negative validation results in MINT transactions with invalid baton
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-04T11:21:14.682Z

Reserved: 2020-03-30T00:00:00

Link: CVE-2020-11072

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-05-12T01:15:11.213

Modified: 2024-11-21T04:56:43.600

Link: CVE-2020-11072

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses