QID 983868
QID 983868: Nodejs (npm) Security Update for slp-validate (GHSA-wmx6-vxcf-c3gr)
Versions of `slp-validate` prior to 1.0.1 are vulnerable to a validation bypass. Bitcoin scripts may cause the validation result from `slp-validate` to differ from the specified SLP consensus. This allows an attacker to create a Bitcoin script that causes a hard-fork from the SLP consensus. ## Recommendation Upgrade to version 1.0.1 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-wmx6-vxcf-c3gr for updates pertaining to this vulnerability.
Vendor References
- GHSA-wmx6-vxcf-c3gr -
github.com/advisories/GHSA-wmx6-vxcf-c3gr
CVEs related to QID 983868
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-wmx6-vxcf-c3gr | slp-validate |
|