GHSA-fxc9-7j2w-vx54: mpp has multiple payment bypass and griefing vulnerabilities
Multiple vulnerabilities were discovered which allowed for undesirable behaviors, including:
- Performing free
tempo/chargerequests - Replaying existing
tempo/chargerequests - Performing free
tempo/sessionrequests - Piggybacking off existing
tempo/sessionchannels - Griefing existing
tempo/sessionchannels - Manipulate the fee payer of a
tempo/chargeortempo/sessionhandler into paying for requests - Replaying existing
stripe/chargerequests
References
Code Behaviors & Features
Detect and mitigate GHSA-fxc9-7j2w-vx54 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →