Scan to Download Gate App
qrCode
More Download Options
Don't remind me again today

XRP Ledger warns that xrpl.js has a security vulnerability, which may pose a Supply Chain attack risk.

robot
Abstract generation in progress

The XRP Ledger Foundation warns that recent versions of the xrpl JavaScript library have potential security vulnerabilities. This library is widely used to build applications that interact with the XRP Ledger. The vulnerabilities were discovered by Aikido Security researcher Charlie Eriksen and may allow attackers to steal users’ Private Keys, posing a serious Supply Chain attack risk. The affected versions are v4.2.1 to v4.2.4 and v2.14.2, limited to code hosted on NPM. The Foundation has released a fixed version, v4.2.5, and recommends that relevant projects upgrade as soon as possible. The vulnerability does not affect the XRP Ledger itself or its GitHub repository. (TheBlock)

XRP0.22%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)