Vulnerability Details CVE-2020-11071
SLPJS (npm package slpjs) before version 0.27.2, has a vulnerability where users could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet could allow spending of the affected tokens which would result in the destruction of a user's minting baton. This is fixed in version 0.27.2.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 46.7%
CVSS Severity
CVSS v3 Score 8.6
CVSS v2 Score 5.0
Products affected by CVE-2020-11071
-
cpe:2.3:a:simpleledger:slpjs:-
-
cpe:2.3:a:simpleledger:slpjs:0.10.2
-
cpe:2.3:a:simpleledger:slpjs:0.10.4
-
cpe:2.3:a:simpleledger:slpjs:0.10.5
-
cpe:2.3:a:simpleledger:slpjs:0.11.2
-
cpe:2.3:a:simpleledger:slpjs:0.11.3
-
cpe:2.3:a:simpleledger:slpjs:0.11.4
-
cpe:2.3:a:simpleledger:slpjs:0.12.2
-
cpe:2.3:a:simpleledger:slpjs:0.14.0
-
cpe:2.3:a:simpleledger:slpjs:0.15.13
-
cpe:2.3:a:simpleledger:slpjs:0.15.3
-
cpe:2.3:a:simpleledger:slpjs:0.16.0
-
cpe:2.3:a:simpleledger:slpjs:0.16.1
-
cpe:2.3:a:simpleledger:slpjs:0.16.2
-
cpe:2.3:a:simpleledger:slpjs:0.16.3
-
cpe:2.3:a:simpleledger:slpjs:0.17.0
-
cpe:2.3:a:simpleledger:slpjs:0.18.0
-
cpe:2.3:a:simpleledger:slpjs:0.18.2
-
cpe:2.3:a:simpleledger:slpjs:0.18.4
-
cpe:2.3:a:simpleledger:slpjs:0.21.1
-
cpe:2.3:a:simpleledger:slpjs:0.21.4
-
cpe:2.3:a:simpleledger:slpjs:0.22.0