Incorrect Comparison Affecting slp-validate package, versions <1.2.2


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.07% (34th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-SLPVALIDATE-597083
  • published31 Jul 2020
  • disclosed31 Jul 2020
  • creditUnknown

Introduced: 31 Jul 2020

CVE-2020-15131  (opens in a new tab)
CWE-697  (opens in a new tab)

How to fix?

Upgrade slp-validate to version 1.2.2 or higher.

Overview

slp-validate is a Lightweight SLP validator with pre-broadcast validation and burn protection.

Affected versions of this package are vulnerable to Incorrect Comparison. There is a vulnerability to false-positive validation outcomes for the NFT1 Child Genesis transaction type. A poorly implemented SLP wallet or opportunistic attacker could create a seemingly valid NFT1 child token without burning any of the NFT1 Group token type as is required by the NFT1 specification.

References

CVSS Scores

version 3.1