Improper Input Validation Affecting uma-sdk package, versions [,1.2.2)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-UMASDK-8161314
- published 3 Oct 2024
- disclosed 1 Oct 2024
- credit Unknown
How to fix?
Upgrade uma-sdk
to version 1.2.2 or higher.
Overview
uma-sdk is a Python SDK for UMA (universal money address)
Affected versions of this package are vulnerable to Improper Input Validation via the lnurlp
request parsing function due to improper validation of the receiver address component of the URL. This could lead to unexpected behavior or vulnerabilities in systems processing this data.