CVE-2020-11072
In SLP Validate (npm package slp-validate) before version 1.2.1, users could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet could allow spending of the affected tokens which would result in the destruction of a user's minting baton. This has been fixed in slp-validate in version 1.2.1. Additonally, slpjs version 0.27.2 has a related fix under related CVE-2020-11071.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
- EPSS probability
- 0.24%
- CWE
- CWE-697
- Published
- 2020-05-12
- Last modified
- 2026-03-14
Affected products
- simpleledger slp-validate
Weakness type
Related vulnerabilities
- CVE-2025-3102 — SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
- CVE-2024-24621 — Softaculous Webuzo Authentication Bypass
- CVE-2021-3833 — Integria IMS incorrect authorization
- CVE-2020-8864 — This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-86
- CVE-2025-48952 — NetAlertX has Password Bypass Vulnerability due to Loose Comparison in PHP
- CVE-2024-34340 — Authentication Bypass when using using older password hashes
- CVE-2022-43621 — This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-19
- CVE-2020-11071 — False-negative validation results in MINT transactions with invalid baton