Skip to content

Creator Verification Error when Bubblegum Activate

High
austbot published GHSA-8r76-fr72-j32w Dec 10, 2022

Package

cargo mpl-bubblegum (Rust)

Affected versions

< 0.6.0

Patched versions

0.6.0 >=
cargo mpl-token-metadata (Rust)
1.5.0 >
1.6.3 >=

Description

This was an error found by @metamania01 of the Audit Company Solshield.

It allowed one to verify a creator that did not sign by making use of a provision in Token Metadata that allows Creators who have signed compressed nfts to allow them to decompress with verified creators.

The issue is now patched.
For more info see.
https://twitter.com/thehasheddude/status/1601642138143375360

Severity

High

CVE ID

No known CVE

Weaknesses

No CWEs