Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j2cr-jc39-wpx5

Опубликовано: 07 июл. 2023
Источник: github
Github: Прошло ревью

Описание

Barberry Security Advisory - regarding x/auth periodic vesting accounts

Impact

In PeriodicVestingAccount, defined in x/auth, an attacker can initialize a victim's account as a malicious vesting account, which allows deposits but does not allow withdrawals. When the user then deposits funds into their account, those funds are locked forever, and the user is not able to withdraw them.

Patches

>= v0.46.13 for Cosmos SDK v0.46.x >= v0.47.3 for Cosmos SDK v0.47.x

If a network backported periodic vesting accounts to earlier versions of the SDK, those networks are affected too.

Workarounds

There is no workaround for this issue. Upgrade immediately.

References

Пакеты

Наименование

github.com/cosmos/cosmos-sdk

go
Затронутые версииВерсия исправления

>= 0.46.0, <= 0.46.12

0.46.13

Наименование

github.com/cosmos/cosmos-sdk

go
Затронутые версииВерсия исправления

>= 0.47.0, <= 0.47.2

0.47.3