QID 983141
QID 983141: Nodejs (npm) Security Update for slpjs (GHSA-425c-ccf3-3jrr)
Security update has been released for slpjs to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation result of the slpjs npm package. An attacker could create a specially crafted Bitcoin script in order to cause a hard-fork from the SLP consensus.
Solution
All versions > 0.21.3 are patched.Workaround:
Upgrade to any version >= 0.21.4.
Upgrade to any version >= 0.21.4.
Vendor References
- GHSA-425c-ccf3-3jrr -
github.com/advisories/GHSA-425c-ccf3-3jrr
CVEs related to QID 983141
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-425c-ccf3-3jrr | slpjs |
|