Description
In the npm package named “slpjs”, versions prior to 0.27.4 are vulnerable to false-positive validation outcomes for the NFT1 Child Genesis transaction type.
Recommendation
Update the slpjs
package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.27.4
- Patched version(s): 0.27.4
References
Related Issues
- Improper Verification of Cryptographic Signature in node-forge - CVE-2022-24772
- XSS vulnerability that affects bootstrap (GHSA-3mgp-fx93-9xv5) - CVE-2018-20676
- follow-redirects' Proxy-Authorization header kept across hosts - CVE-2024-28849
- Hidden fields can be leaked on readable collections in Payload - CVE-2023-30843
- Tags:
- npm
- slpjs
Anything's wrong? Let us know Last updated on January 09, 2023