
Cloud Vulnerability DB
A community-led vulnerabilities database
A high severity vulnerability was identified in the vp-toolkit npm package (GHSA-p94w-42g3-f7h4), affecting versions below 0.2.2. The vulnerability was discovered and published to the GitHub Advisory Database on March 6, 2020, with the latest update on January 9, 2023. The issue affects the verifier component of the vp-toolkit package (GitHub Advisory).
The vulnerability exists in the verifyVerifiableCredential() method, which while checking the cryptographic integrity of the Verifiable Credential, fails to verify if the credential.issuer DID matches the signer of the credential. This oversight in the verification process creates a security gap in the credential verification system (GitHub Advisory).
The vulnerability allows holders to potentially (re)create authentic credentials after receiving a credential, compromising the integrity of the verification system. This affects the verifier's ability to trust the authenticity of credentials processed through the toolkit (GitHub Advisory).
A patch has been released in version 0.2.2 of the vp-toolkit. As a workaround, for verifiers who trust certain issuers for specific credentials, it is recommended to trust the issuer's public key from the credential.proof.verificationMethod field (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."