Utils.readChallengeTx does not verify the server account signature
Description
js-stellar-sdk is a Javascript library for communicating with a Stellar Horizon server. The Utils.readChallengeTx function used in SEP-10 Stellar Web Authentication states in its function documentation that it reads and validates the challenge transaction including verifying that the serverAccountID has signed the transaction. In js-stellar-sdk before version 8.2.3, the function does not verify that the server has signed the transaction. Applications that also used Utils.verifyChallengeTxThreshold or Utils.verifyChallengeTxSigners to verify the signatures including the server signature on the challenge transaction are unaffected as those functions verify the server signed the transaction. Applications calling Utils.readChallengeTx should update to version 8.2.3, the first version with a patch for this vulnerability, to ensure that the challenge transaction is completely valid and signed by the server creating the challenge transaction.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
stellar-sdknpm | < 8.2.3 | 8.2.3 |
Affected products
2- stellar/js-stellar-sdkv5Range: < 8.2.3
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-6cgh-hjpw-q3gqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-32738ghsaADVISORY
- github.com/stellar/js-stellar-sdk/commit/6f0bb889c2d10b431ddd5f4a1bcdd519c80430b3ghsaWEB
- github.com/stellar/js-stellar-sdk/releases/tag/v8.2.3ghsax_refsource_MISCWEB
- github.com/stellar/js-stellar-sdk/security/advisories/GHSA-6cgh-hjpw-q3gqghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.