Impact
Improper Validation of Specified Quantity in Input allows an unauthenticated remote client to attach a key_authorization field to a Tempo payment request, causing the sponsor to pay for an access key that the client did not authorize and inflating the transaction gas cost by a large multiplier. The attacker gains a persistent key they paid nothing for, while the sponsor incurs potentially massive gas fees.
Affected Systems
ZenHive mpp, all releases from 0.2.0 up to but not including version 0.16.1, is affected.
Risk and Exploitability
The CVSS score indicates high severity (8.3). No EPSS score is available and the vulnerability is not listed in KEV, but the attack vector is likely remote unauthenticated, requiring a client to send a specially crafted Tempo request over the network. An attacker can immediately force the sponsor to pay inflated gas costs and provision an unauthorized access key without further privileges.
OpenCVE Enrichment