Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-33964

Опубликовано: 31 мая 2023
Источник: nvd
CVSS3: 8.6
CVSS3: 7.5
EPSS Низкий

Описание

mx-chain-go is an implementation of the MultiversX blockchain protocol written in the Go language. Metachain cannot process a cross-shard miniblock. Prior to version 1.4.16, an invalid transaction with the wrong username on metachain is not treated correctly on the metachain transaction processor. This is strictly a processing issue that could have happened on MultiversX chain. If an error like this had occurred, the metachain would have stopped notarizing blocks from the shard chains. The resuming of notarization is possible only after applying a patched binary version. A patch in version 1.4.16 introduces processIfTxErrorCrossShard for the metachain transaction processor. There are no known workarounds for this issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:multiversx:mx-chain-go:*:*:*:*:*:go:*:*
Версия до 1.4.16 (исключая)

EPSS

Процентиль: 37%
0.00162
Низкий

8.6 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-20
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 8.6
github
больше 2 лет назад

mx-chain-go does not treat invalid transaction with wrong username correctly

EPSS

Процентиль: 37%
0.00162
Низкий

8.6 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-20
NVD-CWE-noinfo