Multiple vulnerabilities were discovered which allowed for undesirable behaviors, including:
- Performing free tempo/charge requests
- Replaying existing tempo/charge requests
- Performing free tempo/session requests
- Piggybacking off existing tempo/session channels
- Griefing existing tempo/session channels
- Manipulate the fee payer of a tempo/charge or tempo/session handler into paying for requests
- Replaying existing stripe/charge requests
The issues are patched in 0.8.0
There are no workarounds available for these vulnerabilities
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 9.3 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-fxc9-7j2w-vx54 ↗ |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| rust | mpp | < 0.8.0 | 0.8.0 | — |