GHSA-8r76-fr72-j32w

Suggest an improvement
Source
https://github.com/advisories/GHSA-8r76-fr72-j32w
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/12/GHSA-8r76-fr72-j32w/GHSA-8r76-fr72-j32w.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-8r76-fr72-j32w
Published
2022-12-12T22:02:42Z
Modified
2022-12-12T22:02:42Z
Summary
Creator Verification Error when Bubblegum Activate
Details

This was an error found by @metamania01 of the Audit Company Solshield.

It allowed one to verify a creator that did not sign by making use of a provision in Token Metadata that allows Creators who have signed compressed nfts to allow them to decompress with verified creators.

The issue is now patched. For more info see. https://twitter.com/thehasheddude/status/1601642138143375360

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2022-12-12T22:02:42Z"
}
References

Affected packages

crates.io / mpl-bubblegum

Package

Name
mpl-bubblegum
View open source insights on deps.dev
Purl
pkg:cargo/mpl-bubblegum

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.0

crates.io / mpl-token-metadata

Package

Name
mpl-token-metadata
View open source insights on deps.dev
Purl
pkg:cargo/mpl-token-metadata

Affected ranges

Type
SEMVER
Events
Introduced
1.5.0
Fixed
1.6.3