Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6fgm-x6ff-w78f

Опубликовано: 12 фев. 2025
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

Potential Denial-of-Service condition leading to temporary disability in IBC transfers to the native chain

Impact

Chains using affected versions of Packet Forward Middleware in their IBC Transfer stack are vulnerable to an attack in which there is a potential denial of service. This affects IBC transfers for any asset which is being transferred between another chain and its native chain.

We recommend upgrading as soon as possible.

THIS IS A STATE BREAKING CHANGE

Patches

Versions 7.2.1 and 8.1.1 are patched.

Workarounds

N/A

References

N/A

Пакеты

Наименование

github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v7

go
Затронутые версииВерсия исправления

< 7.2.1

7.2.1

Наименование

github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v8

go
Затронутые версииВерсия исправления

< 8.1.1

8.1.1

Наименование

github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v4

go
Затронутые версииВерсия исправления

Отсутствует

Наименование

github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v5

go
Затронутые версииВерсия исправления

Отсутствует

Наименование

github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v6

go
Затронутые версииВерсия исправления

Отсутствует

6.9 Medium

CVSS4

6.9 Medium

CVSS4