GHSA-2p6r-37p9-89p2

Suggest an improvement
Source
https://github.com/advisories/GHSA-2p6r-37p9-89p2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/10/GHSA-2p6r-37p9-89p2/GHSA-2p6r-37p9-89p2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-2p6r-37p9-89p2
Aliases
Related
Published
2021-10-21T17:46:57Z
Modified
2023-11-08T04:06:52.479634Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Authz Module Non-Determinism
Details

Impact

Consensus failure for 0.43.x and 0.44.{0,1} users. Funds and balances are safe.

Patches

0.44.2

Workarounds

Manually patch the code.


Full details posted in https://forum.cosmos.network/t/cosmos-sdk-vulnerability-retrospective-security-advisory-jackfruit-october-12-2021/5349.

Database specific
{
    "nvd_published_at": "2021-10-20T18:15:00Z",
    "github_reviewed_at": "2021-10-20T15:36:34Z",
    "severity": "MODERATE",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-754"
    ]
}
References

Affected packages

Go / github.com/cosmos/cosmos-sdk

Package

Name
github.com/cosmos/cosmos-sdk
View open source insights on deps.dev
Purl
pkg:golang/github.com/cosmos/cosmos-sdk

Affected ranges

Type
SEMVER
Events
Introduced
0.43.0
Fixed
0.44.2