mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the stripe/charge payment method did not check Stripe's Idempotent-Replayed response header when creating Paymen…
高危 CVSS 8.1
摘要
mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the stripe/charge payment method did not check Stripe's Idempotent-Replayed response header when creating PaymentIntents. An attacker could replay a valid credential containing the same spt token against a new challenge, and the server would accept the replayed Stripe PaymentIntent as a new successful payment without actually charging the customer again. This allowed an attacker to pay once and consume unlimi…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://github.com/wevm/mppx/commit/b2b1a0b60506fc71aa80b8a025084949dca1a994 Patch
- https://github.com/wevm/mppx/releases/tag/mppx@0.4.11 Release Notes
- https://github.com/wevm/mppx/security/advisories/GHSA-8mhj-rffc-rcvw Patch
时间线
- nvd_ingest NVD