OSV 1.4.0 · github-reviewed · 修改于 2020-02-29 00:38
发布时间
2020-03-06 09:16
GitHub 审查时间
2020-02-29 00:38
NVD 发布时间
—
源文件
advisories/github-reviewed/2020/03/GHSA-p94w-42g3-f7h4/GHSA-p94w-42g3-f7h4.json
The verifyVerifiableCredential() method check the cryptographic integrity of the Verifiable Credential, but it does not check if the credential.issuer DID matches the signer of the credential.
The verifier is impacted by this vulnerability.
Patch will be available in version 0.2.2.
In case you trust certain issuers for certain credentials as a verifier, trust the issuer's public key from the credential.proof.verificationMethod field.
If you have any questions or comments about this advisory: