UNKNOWNGHSA-fxc9-7j2w-vx54

mpp has multiple payment bypass and griefing vulnerabilities

Platform

rust

Component

mpp

Fixed in

0.8.0

### Impact Multiple vulnerabilities were discovered which allowed for undesirable behaviors, including: - Performing free `tempo/charge` requests - Replaying existing `tempo/charge` requests - Performing free `tempo/session` requests - Piggybacking off existing `tempo/session` channels - Griefing existing `tempo/session` channels - Manipulate the fee payer of a `tempo/charge` or `tempo/session` handler into paying for requests - Replaying existing `stripe/charge` requests ### Patches The issues are patched in 0.8.0 ### Workarounds There are no workarounds available for these vulnerabilities

How to fix

No official patch available. Check for workarounds or monitor for updates.

Monitor your dependencies automatically

Get notified when new vulnerabilities affect your projects. Free forever.

Start free