This repository has been archived by the owner on Jun 11, 2024. It is now read-only.
Lack of ChannelData schema validation in InitializeMessageRecoveryCommand #8621
Labels
Milestone
Description
The ChannelData provided by the user in the
InitializeMessageRecoveryCommand
command is decoded but not validated. The inclusion proof prevents rogue values from being used (although a malicious chain could create invalid accounts). We also note that passing the empty string value to trigger a non-inclusion proof is possible, but the decoding would fail in theexecute
method.Which version(s) does this affect? (Environment, OS, etc...)
v6.0.0-beta.2
The text was updated successfully, but these errors were encountered: