We’ve disclosed3385vulnerabilities
by Snyk Security
Researchers
Avoid using all malicious instances of the @solana/web3.js
package.
@lodestar/reqresp is an A Typescript implementation of the Ethereum Consensus Req/Resp protocol
Affected versions of this package are vulnerable to Improper Validation of Integrity Check Value. An attacker can manipulate the processing of uncompressed data chunks by providing a malformed input that bypasses the checksum verification.
vyper is a Pythonic Smart Contract Language for the EVM.
Affected versions of this package are vulnerable to Improper Check or Handling of Exceptional Conditions due to a failure to verify the success flag of calls to the precompiles EcRecover (0x1)
and Identity (0x4)
. An attacker can exploit this by providing a specific amount of gas to intentionally make these calls fail while allowing the overall execution to continue.
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to improper neutralization of user-controllable input before it is placed in output that is served as a web page. An attacker can execute arbitrary script in the context of the interface by injecting malicious scripts.
Note:
This is only exploitable if the attacker is authenticated as a user that belongs to management groups SuperUser
, Admin
, or Maintainer
.
by Snyk Security
Researchers
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.