False-negative validation results in MINT transactions with invalid baton
Critical severity
GitHub Reviewed
Published
May 11, 2020
in
simpleledger/slp-validate.js
•
Updated Jan 9, 2023
Description
Reviewed
May 12, 2020
Published to the GitHub Advisory Database
May 12, 2020
Last updated
Jan 9, 2023
Impact
Users could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet could allow spending of the affected tokens which would result in the destruction of a user's minting baton.
Patches
npm package slp-validate has been patched and published as version 1.2.1.
Workarounds
Upgrade to slp-validate 1.2.1.
References
For more information
If you have any questions or comments about this advisory:
References