{"id":"GHSA-8r76-fr72-j32w","aliases":[],"url":"https://o3.security/vulnerability/GHSA-8r76-fr72-j32w","summary":"Creator Verification Error when Bubblegum Activate","details":"This was an error found by @metamania01 of the Audit Company Solshield.\n\nIt allowed one to verify a creator that did not sign by making use of a provision in Token Metadata that allows Creators who have signed compressed nfts to allow them to decompress with verified creators.\n\nThe issue is now patched.\nFor more info see.\nhttps://twitter.com/thehasheddude/status/1601642138143375360","published":"2022-12-12T22:02:42Z","modified":"2022-12-12T22:02:42Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"mpl-bubblegum","fixedVersion":"0.6.0"},{"ecosystem":"crates.io","name":"mpl-token-metadata","fixedVersion":"1.6.3"}],"fix":{"url":"https://github.com/metaplex-foundation/metaplex-program-library/commit/c18591a7ce9bb561940cb94df4b7c35ef9cc0f57","label":"metaplex-foundation/metaplex-program-library@c18591a"},"references":[{"type":"WEB","url":"https://github.com/metaplex-foundation/metaplex-program-library/security/advisories/GHSA-8r76-fr72-j32w"},{"type":"WEB","url":"https://github.com/metaplex-foundation/metaplex-program-library/commit/c18591a7ce9bb561940cb94df4b7c35ef9cc0f57"},{"type":"PACKAGE","url":"https://github.com/metaplex-foundation/metaplex-program-library"},{"type":"WEB","url":"https://twitter.com/thehasheddude/status/1601642138143375360"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2022-12-12T22:02:42Z"}}