GHSA-6jmr-jfh7-xg3h

Suggest an improvement
Source
https://github.com/advisories/GHSA-6jmr-jfh7-xg3h
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/07/GHSA-6jmr-jfh7-xg3h/GHSA-6jmr-jfh7-xg3h.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-6jmr-jfh7-xg3h
Aliases
Published
2020-07-30T14:58:53Z
Modified
2026-05-07T05:01:49Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
False-positive validity for NFT1 genesis transactions
Details

Impact

In the npm package named "slp-validate", versions prior to 1.2.2 are vulnerable to false-positive validation outcomes for the NFT1 Child Genesis transaction type. A poorly implemented SLP wallet or opportunistic attacker could create a seemingly valid NFT1 child token without burning any of the NFT1 Group token type as is required by the NFT1 specification.

Patches

npm package "slp-validate" has been patched and is published and tagged as version 1.2.2.

Workarounds

Upgrade to slp-validate 1.2.2.

References

For more information

If you have any questions or comments about this advisory please open an issue in the slp-validate repository.

Database specific
{
    "cwe_ids":  [
        "CWE-697"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-07-30T14:54:40Z",
    "nvd_published_at":  null,
    "severity":  "CRITICAL"
}
References

Affected packages

npm / slp-validate

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.2.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/07/GHSA-6jmr-jfh7-xg3h/GHSA-6jmr-jfh7-xg3h.json"