GHSA-4jmp-x7mh-rgmr
Summary
The anti-slashing is not effective if the attacker can access EOTS manager endpoints.
Impact
If the EOTS manager endpoints are open to public without HMAC protection, the attacker can manually cause slashing of the finality provider through the RPC endpoints
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/babylonlabs-io/finality-provider/security/advisories/GHSA-4jmp-x7mh-rgmr, https://github.com/babylonlabs-io/finality-provider/commit/721bf5b7a271ada1679a67496c9bc3516c339390, https://github.com/babylonlabs-io/finality-provider
