Vulnerabilities/

Incorrect Account Used for Signing

Severity:
High

Description

Anybody using this library to sign with a BIP44 account other than the first account may be affected. If a user is signing with the first account (i.e. the account at index 0), or with the legacy MEW/MyCrypto HD path, they are not affected.

Recommendation

Update the @metamask/eth-ledger-bridge-keyring package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@metamask/eth-ledger-bridge-keyring
Anything's wrong? Let us know Last updated on January 09, 2023