GHSA-7c94-gvvj-r3mg

Suggest an improvement
Source
https://github.com/advisories/GHSA-7c94-gvvj-r3mg
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-7c94-gvvj-r3mg/GHSA-7c94-gvvj-r3mg.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7c94-gvvj-r3mg
Published
2023-06-05T20:36:58Z
Modified
2023-06-05T20:36:58Z
Summary
cheqd-node affected by Inter-blockchain Communication (IBC) protocol "Huckleberry" vulnerability
Details

Impact

This vulnerability affects the ibc-go package for those running full nodes, dubbed "Huckleberry". According to their advisory:

This issue is low-severity in general, and it has a low impact and likelihood of exploitation. Depending on how a full node is architected, this issue could potentially yield a high or critical severity vulnerability.

There is no vulnerability in the DID/resource modules for cheqd-node.

Patches

Node operators are requested to upgrade to cheqd-node v1.4.2. This is a non-state breaking release, and does not require a coordinated upgrade across all node operators.

Workarounds

No. Node operators are recommended to upgrade to the latest release version.

References

Database specific
{
    "cwe_ids":  [],
    "github_reviewed":  true,
    "github_reviewed_at":  "2023-06-05T20:36:58Z",
    "nvd_published_at":  null,
    "severity":  "LOW"
}
References

Affected packages

Go / github.com/cheqd/cheqd-node

Package

Name
github.com/cheqd/cheqd-node
View open source insights on deps.dev
Purl
pkg:golang/github.com/cheqd/cheqd-node

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.4.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-7c94-gvvj-r3mg/GHSA-7c94-gvvj-r3mg.json"