为 MPPX 支付方式提供了条件性的免费访问包装器。在 版本低于 3.0.0 以及 版本低于 1.0.4 的旧版本中,这些包会从客户端提供的凭证 中读取一个钱包地址,检查该公共地址是否满足链上配置的条件的结果,返回一个成功的免费访问凭证,而无需调用被包装的支付验证器,也无需证明调用者实际上控制着该钱包。 未经验证的攻击者可以任意指定一个符合条件的钱包地址,从而获得本应需要付费才能访问的内容;此外,缓存的授权凭证可以在配置的缓存有效期内被重复使用。 修复后的版本仅在确认支付者已建立钱包控制权的前提下,才允许免费访问授
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| @insumermodel | mppx-condition-gate | < 3.0.0 |
affected |
| @insumermodel | mppx-token-gate | < 1.0.4 |
affected |
| douglasborthwick-crypto | mppx-condition-gate | < b1d9935a57ba6d32da49eead1bfb459ad0cd55ab |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| douglasborthwick-crypto | mppx-condition-gate | < b1d9935a57ba6d32da49eead1bfb459ad0cd55ab | - |
|
| @insumermodel | mppx-condition-gate | < 3.0.0 | - |
|
| @insumermodel | mppx-token-gate | < 1.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet