GHSA-ff5x-w9wg-h275

Suggest an improvement
Source
https://github.com/advisories/GHSA-ff5x-w9wg-h275
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/03/GHSA-ff5x-w9wg-h275/GHSA-ff5x-w9wg-h275.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-ff5x-w9wg-h275
Published
2020-03-06T01:15:46Z
Modified
2020-02-28T16:38:18Z
Summary
Holder can generate proof of ownership for credentials it does not control in vp-toolkit
Details

Impact

The verifyVerifiablePresentation() method check the cryptographic integrity of the Verifiable Presentation, but it does not check if the credentialSubject.id DID matches the signer of the VP proof.

The verifier is impacted by this vulnerability.

Patches

Patch will be available in version 0.2.2.

Workarounds

  • Compute the address out of the verifiablePresentation.proof.n.verificationMethod using getAddressFromPubKey() from crypt-util@0.1.5 and match it with the credentialSubject.id address from the credential.

References

Github issue

For more information

If you have any questions or comments about this advisory:

Database specific
{
    "cwe_ids":  [],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-02-28T16:38:18Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / vp-toolkit

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.2.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/03/GHSA-ff5x-w9wg-h275/GHSA-ff5x-w9wg-h275.json"