Skip to content
This repository was archived by the owner on May 24, 2022. It is now read-only.
This repository was archived by the owner on May 24, 2022. It is now read-only.

Specify a commit hash for icon downloads #535

@Tbaut

Description

@Tbaut

Fether references a third-party repository ( atomiclabs/cryptocurrency-icons ) for its logo
images without specifying specific commit hash versions. This could allow the third-party to
perform a denial-of-service attack against the users of the Fether wallet by uploading large
logo images, maliciously crafted to result in exorbitant memory usage.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions