OSV 1.4.0 · github-reviewed · 修改于 2021-01-08 07:43
发布时间
2020-07-30 22:58
GitHub 审查时间
2020-07-30 22:44
NVD 发布时间
—
源文件
advisories/github-reviewed/2020/07/GHSA-cc2p-4jhr-xhhx/GHSA-cc2p-4jhr-xhhx.json
In the npm package named "slpjs", versions prior to 0.27.4 are vulnerable to false-positive validation outcomes for the NFT1 Child Genesis transaction type. A poorly implemented SLP wallet or opportunistic attacker could create a seemingly valid NFT1 child token without burning any of the NFT1 Group token type as is required by the NFT1 specification.
npm package "slpjs" has been patched and is published and tagged as version 0.27.4.
Upgrade to slpjs 0.27.4.
If you have any questions or comments about this advisory please open an issue in the slp-validate repository.