{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-18T19:06:40.699","vulnerabilities":[{"cve":{"id":"CVE-2020-11071","sourceIdentifier":"security-advisories@github.com","published":"2020-05-12T01:15:11.150","lastModified":"2024-11-21T04:56:43.487","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"SLPJS (npm package slpjs) before version 0.27.2, has a vulnerability where users could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet could allow spending of the affected tokens which would result in the destruction of a user's minting baton. This is fixed in version 0.27.2."},{"lang":"es","value":"SLPJS (paquete slpjs de npm) versiones anteriores a 0.27.2, presenta una vulnerabilidad donde los usuarios podrían experimentar resultados de comprobación falsos negativos para las operaciones de transacción MINT. Una billetera SLP mal implementada podría permitir el gasto de los tokens afectados, lo que resultaría en la destrucción minting baton del usuario. Esto es corrigido en la versión 0.27.2."}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":4.0}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-697"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-697"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:simpleledger:slpjs:*:*:*:*:*:node.js:*:*","versionEndExcluding":"0.27.2","matchCriteriaId":"035AB245-62DC-434B-A63F-D1AC45D95DFC"}]}]}],"references":[{"url":"https://github.com/simpleledger/slpjs/commit/3671be2ffb6d4cfa94c00c6dc8649d1ba1d75754","source":"security-advisories@github.com","tags":["Patch","Tool Signature"]},{"url":"https://github.com/simpleledger/slpjs/security/advisories/GHSA-jc83-cpf9-q7c6","source":"security-advisories@github.com","tags":["Tool Signature"]},{"url":"https://github.com/simpleledger/slpjs/commit/3671be2ffb6d4cfa94c00c6dc8649d1ba1d75754","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Tool Signature"]},{"url":"https://github.com/simpleledger/slpjs/security/advisories/GHSA-jc83-cpf9-q7c6","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Tool Signature"]}]}}]}