CVE-2021-32738
Description
js-stellar-sdk is a Javascript library for communicating with a Stellar Horizon server. The Utils.readChallengeTx function used in SEP-10 Stellar Web Authentication states in its function documentation that it reads and validates the challenge transaction including verifying that the serverAccountID has signed the transaction. In js-stellar-sdk before version 8.2.3, the function does not verify that the server has signed the transaction. Applications that also used Utils.verifyChallengeTxThreshold or Utils.verifyChallengeTxSigners to verify the signatures including the server signature on the challenge transaction are unaffected as those functions verify the server signed the transaction. Applications calling Utils.readChallengeTx should update to version 8.2.3, the first version with a patch for this vulnerability, to ensure that the challenge transaction is completely valid and signed by the server creating the challenge transaction.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
stellar-sdknpm | < 8.2.3 | 8.2.3 |
Affected products
3- stellar/js-stellar-sdkv5Range: < 8.2.3
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-6cgh-hjpw-q3gqghsaADVISORY
- github.com/stellar/js-stellar-sdk/releases/tag/v8.2.3nvdRelease NotesThird Party AdvisoryWEB
- github.com/stellar/js-stellar-sdk/security/advisories/GHSA-6cgh-hjpw-q3gqnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-32738ghsaADVISORY
- github.com/stellar/js-stellar-sdk/commit/6f0bb889c2d10b431ddd5f4a1bcdd519c80430b3ghsaWEB
News mentions
0No linked articles in our index yet.