CVE-2020-15131
Summary
| CVE | CVE-2020-15131 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-30 15:15:00 UTC |
| Updated | 2020-08-03 15:22:00 UTC |
| Description | In SLP Validate (npm package slp-validate) before version 1.2.2, there is a vulnerability to false-positive validation outcomes for the NFT1 Child Genesis transaction type. A poorly implemented SLP wallet or opportunistic attacker could create a seemingly valid NFT1 child token without burning any of the NFT1 Group token type as is required by the NFT1 specification. This is fixed in version 1.2.2. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| False-positive validity for NFT1 genesis transactions · Advisory · simpleledger/slp-validate.js · GitHub |
CONFIRM |
github.com |
Third Party Advisory |
| critical update for NFT child genesis validation · simpleledger/slp-validate.js@3963cf9 · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 983862 Nodejs (npm) Security Update for slp-validate (GHSA-6jmr-jfh7-xg3h)