Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
False-negative validation results in MINT transactions with invalid baton
Vulnerability Description
In SLP Validate (npm package slp-validate) before version 1.2.1, users could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet could allow spending of the affected tokens which would result in the destruction of a user's minting baton. This has been fixed in slp-validate in version 1.2.1. Additonally, slpjs version 0.27.2 has a related fix under related CVE-2020-11071.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Vulnerability Type
不充分的比较
Vulnerability Title
SLP Validate 安全漏洞
Vulnerability Description
slp-validate是一款轻量级SLP(简单账本协议)验证器,它具有预广播验证和刻录保护等功能。slpjs是一款用于验证和构建简单账本协议(SLP)的JavaScript库。 SLP Validate 1.2.1之前版本中存在安全漏洞。攻击者可利用该漏洞破坏用于产生代币(token)的baton。
CVSS Information
N/A
Vulnerability Type
N/A