Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x5f3-qmwj-4f84

Опубликовано: 15 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Authentication bypass by capture-replay in github.com/cosmos/ethermint

Cosmos Network Ethermint <= v0.4.0 is affected by a cross-chain transaction replay vulnerability in the EVM module. Since ethermint uses the same chainIDEpoch and signature schemes with ethereum for compatibility, a verified signature in ethereum is still valid in ethermint with the same msg content and chainIDEpoch, which enables "cross-chain transaction replay" attack.

Specific Go Packages Affected

github.com/cosmos/ethermint/rpc/namespaces/eth

Пакеты

Наименование

github.com/cosmos/ethermint

go
Затронутые версииВерсия исправления

< 0.4.1

0.4.1

EPSS

Процентиль: 40%
0.00179
Низкий

7.5 High

CVSS3

Дефекты

CWE-294
CWE-295

Связанные уязвимости

CVSS3: 7.5
nvd
почти 5 лет назад

Cosmos Network Ethermint <= v0.4.0 is affected by a cross-chain transaction replay vulnerability in the EVM module. Since ethermint uses the same chainIDEpoch and signature schemes with ethereum for compatibility, a verified signature in ethereum is still valid in ethermint with the same msg content and chainIDEpoch, which enables "cross-chain transaction replay" attack.

EPSS

Процентиль: 40%
0.00179
Низкий

7.5 High

CVSS3

Дефекты

CWE-294
CWE-295