Multiple vulnerabilities were discovered which allowed for undesirable behaviors, including:
tempo/charge requeststempo/charge requeststempo/session requeststempo/session channelstempo/session channelstempo/charge or tempo/session handler into paying for requestsstripe/charge requestsThe issues are patched in 0.8.0
There are no workarounds available for these vulnerabilities
0.8.0Exploitability
AV:NAC:LAT:NPR:NUI:NVulnerable System
VC:NVI:HVA:NSubsequent System
SC:HSI:HSA:N9.3/CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N