Improper Input Validation Affecting uma-sdk package, versions [,1.2.2)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-PYTHON-UMASDK-8161314
  • published 3 Oct 2024
  • disclosed 1 Oct 2024
  • credit Unknown

Introduced: 1 Oct 2024

CVE NOT AVAILABLE CWE-20 Open this link in a new tab

How to fix?

Upgrade uma-sdk to version 1.2.2 or higher.

Overview

uma-sdk is a Python SDK for UMA (universal money address)

Affected versions of this package are vulnerable to Improper Input Validation via the lnurlp request parsing function due to improper validation of the receiver address component of the URL. This could lead to unexpected behavior or vulnerabilities in systems processing this data.

References

CVSS Scores

version 4.0
version 3.1
Expand this section

Snyk

Recommended
6.9 medium
  • Attack Vector (AV)
    Network
  • Attack Complexity (AC)
    Low
  • Attack Requirements (AT)
    None
  • Privileges Required (PR)
    None
  • User Interaction (UI)
    None
  • Confidentiality (VC)
    Low
  • Integrity (VI)
    None
  • Availability (VA)
    None
  • Confidentiality (SC)
    None
  • Integrity (SI)
    None
  • Availability (SA)
    None