1.7.0
3 years ago
2 months ago
Known vulnerabilities in the @keep-network/tbtc-v2 package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Improperly Implemented Security Check for Standard via the creation of a 64-byte transaction that is treated as a node in its Merkle proof. An attacker can produce seemingly valid SPV proofs for fraudulent transactions by publishing specially crafted transactions on the Bitcoin blockchain. This is only exploitable if the attacker calculates an unusual but valid transaction How to fix Improperly Implemented Security Check for Standard? Upgrade | <1.5.2 |