Incorrect Comparison Affecting slpjs package, versions <0.27.4


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.07% (34th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-SLPJS-597082
  • published31 Jul 2020
  • disclosed31 Jul 2020
  • creditUnknown

Introduced: 31 Jul 2020

CVE-2020-15130  (opens in a new tab)
CWE-697  (opens in a new tab)

How to fix?

Upgrade slpjs to version 0.27.4 or higher.

Overview

slpjs is a JavaScript Library for validating and building Simple Ledger Protocol (SLP) token transactions

Affected versions of this package are vulnerable to Incorrect Comparison. There is a vulnerability to false-positive validation outcomes for the NFT1 Child Genesis transaction type. A poorly implemented SLP wallet or opportunistic attacker could create a seemingly valid NFT1 child token without burning any of the NFT1 Group token type as is required by the NFT1 specification.

References

CVSS Scores

version 3.1