Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wq32-8rp4-w2mc

Опубликовано: 27 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Nethermind Juno Potential Denial of Service (DoS) via Integer Overflow

An integer overflow in Nethermind Juno before v0.12.5 within the Sierra bytecode decompression logic within the "cairo-lang-starknet-classes" library could allow remote attackers to trigger an infinite loop (and high CPU usage) by submitting a malicious Declare v2/v3 transaction. This results in a denial-of-service condition for affected Starknet full-node implementations.

Пакеты

Наименование

github.com/NethermindEth/juno

go
Затронутые версииВерсия исправления

< 0.12.5

0.12.5

EPSS

Процентиль: 82%
0.01673
Низкий

7.5 High

CVSS3

Дефекты

CWE-190
CWE-770

Связанные уязвимости

CVSS3: 7.5
nvd
11 месяцев назад

An integer overflow in Nethermind Juno before v.12.05 within the Sierra bytecode decompression logic within the "cairo-lang-starknet-classes" library could allow remote attackers to trigger an infinite loop (and high CPU usage) by submitting a malicious Declare v2/v3 transaction. This results in a denial-of-service condition for affected Starknet full-node implementations.

EPSS

Процентиль: 82%
0.01673
Низкий

7.5 High

CVSS3

Дефекты

CWE-190
CWE-770