Description
The Utils.readChallengeTx function used in SEP-10 Stellar Web Authentication states in its function documentation that it reads and validates the challenge transaction including verifying that the serverAccountID has signed the transaction.
Recommendation
Update the stellar-sdk package to the latest compatible version. Followings are version details:
- Affected version(s): < 8.2.3
- Patched version(s): 8.2.3
References
Related Issues
- xdlocalstorage does not verify request origin - CVE-2020-11610
- Strapi does not verify the access or ID tokens issued during the OAuth flow - CVE-2023-22893
- Strapi: Password Reset Does Not Revoke Existing Refresh Sessions - @strapi/plugin-users-permissions - CVE-2026-22706
- KaTeX's `\includegraphics` does not escape filename - CVE-2024-28245
You might also like:
- Tags:
- npm
- stellar-sdk
Anything's wrong? Let us know Last updated on January 27, 2023


