CVE-2020-11014
Electron-Cash-SLP before version 3.6.2 has a vulnerability.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Electron-Cash-SLP before version 3.6.2 has a vulnerability. All token creators that use the "Mint Tool" feature of the Electron Cash SLP Edition are at risk of sending the minting authority baton to the wrong SLP address. Sending the mint baton to the wrong address will give another party the ability to issue new tokens or permanently destroy future minting capability. This is fixed version 3.6.2.
- CVSS 3.1
- 8.6 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
- EPSS
- 1.57% probability · 74th percentile
- CISA KEV
- Not listed
- Affected
- simpleledger/electron-cash-slp
- Source
- security-advisories@github.com
References
- https://github.com/kristovatlas/rfc/blob/master/bips/bip-li01.mediawikiThird Party Advisory
- https://github.com/simpleledger/Electron-Cash-SLP/commit/ea3912c3d508ba81b280ef7d78648464f7f76fb8Patch, Third Party Advisory
- https://github.com/simpleledger/Electron-Cash-SLP/issues/126Third Party Advisory
- https://github.com/simpleledger/Electron-Cash-SLP/security/advisories/GHSA-cchm-grx2-g873Third Party Advisory
- https://github.com/kristovatlas/rfc/blob/master/bips/bip-li01.mediawikiThird Party Advisory
- https://github.com/simpleledger/Electron-Cash-SLP/commit/ea3912c3d508ba81b280ef7d78648464f7f76fb8Patch, Third Party Advisory
- https://github.com/simpleledger/Electron-Cash-SLP/issues/126Third Party Advisory
- https://github.com/simpleledger/Electron-Cash-SLP/security/advisories/GHSA-cchm-grx2-g873Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.