Skip to content

Creator Verification Error when Bubblegum Activate

High severity GitHub Reviewed Published Dec 10, 2022 in metaplex-foundation/metaplex-program-library • Updated Jan 13, 2023

Package

cargo mpl-bubblegum (Rust)

Affected versions

< 0.6.0

Patched versions

0.6.0
cargo mpl-token-metadata (Rust)
>= 1.5.0, < 1.6.3
1.6.3

Description

This was an error found by @metamania01 of the Audit Company Solshield.

It allowed one to verify a creator that did not sign by making use of a provision in Token Metadata that allows Creators who have signed compressed nfts to allow them to decompress with verified creators.

The issue is now patched.
For more info see.
https://twitter.com/thehasheddude/status/1601642138143375360

References

Published to the GitHub Advisory Database Dec 12, 2022
Reviewed Dec 12, 2022
Last updated Jan 13, 2023

Severity

High

Weaknesses

No CWEs

CVE ID

No known CVE

GHSA ID

GHSA-8r76-fr72-j32w
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.