VDB
Sign up
CRITICAL

GHSA-fxc9-7j2w-vx54

mpp has multiple payment bypass and griefing vulnerabilities

Details

### Impact Multiple vulnerabilities were discovered which allowed for undesirable behaviors, including: - Performing free `tempo/charge` requests - Replaying existing `tempo/charge` requests - Performing free `tempo/session` requests - Piggybacking off existing `tempo/session` channels - Griefing existing `tempo/session` channels - Manipulate the fee payer of a `tempo/charge` or `tempo/session` handler into paying for requests - Replaying existing `stripe/charge` requests

### Patches The issues are patched in 0.8.0

### Workarounds There are no workarounds available for these vulnerabilities

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/mpp
Introduced in: 0Fixed in: 0.8.0

Upgrade mpp to 0.8.0 or newer (ecosystem crates.io).

References