Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-93p5-8fqw-wjx3

Опубликовано: 15 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Authentication bypass by capture-replay in github.com/cosmos/ethermint

Cosmos Network Ethermint <= v0.4.0 is affected by a transaction replay vulnerability in the EVM module. If the victim sends a very large nonce transaction, the attacker can replay the transaction through the application.

Specific Go Packages Affected

github.com/cosmos/ethermint/rpc/namespaces/eth

Пакеты

Наименование

github.com/cosmos/ethermint

go
Затронутые версииВерсия исправления

< 0.4.1

0.4.1

EPSS

Процентиль: 42%
0.00198
Низкий

7.5 High

CVSS3

Дефекты

CWE-287
CWE-294

Связанные уязвимости

CVSS3: 7.5
nvd
почти 5 лет назад

Cosmos Network Ethermint <= v0.4.0 is affected by a transaction replay vulnerability in the EVM module. If the victim sends a very large nonce transaction, the attacker can replay the transaction through the application.

EPSS

Процентиль: 42%
0.00198
Низкий

7.5 High

CVSS3

Дефекты

CWE-287
CWE-294