CVE-2019-16761 describes a vulnerability in the simpleledger slp_validate npm package, specifically versions 1.0.0 and earlier. A specially crafted Bitcoin script could lead to a discrepancy between the intended SLP consensus rules and the validation result of the affected package. This could enable an attacker to trigger a hard-fork from the SLP consensus. The vulnerability has a CVSS score of 6.1 (Medium), indicating a moderate severity. It requires high privileges and user interaction, but can be exploited over the network. The potential impact is high availability and integrity, as it could disrupt the SLP network. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness. All versions of the slp-validate package greater than 1.0.0 have been patched.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0CPE matchmatch criteria | cpe:2.3:a:simpleledger:slp-validate:1.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.