Vulnerability Report: GO-2021-0090
- CVE-2020-15091, GHSA-6jqj-f58p-mrw3
- Affects: github.com/tendermint/tendermint
- Published: Apr 14, 2021
- Modified: May 20, 2024
Proposed commits may contain signatures for blocks not contained within the commit. Instead of skipping these signatures, they cause failure during verification. A malicious proposer can use this to force consensus failures.
Affected Packages
-
PathGo VersionsSymbols
-
from v0.33.0 before v0.34.0-dev1.0.20200702134149-480b995a3172
Aliases
References
- https://github.com/tendermint/tendermint/pull/5426
- https://github.com/tendermint/tendermint/commit/480b995a31727593f58b361af979054d17d84340
- https://github.com/tendermint/tendermint/issues/4926
- https://vuln.go.dev/ID/GO-2021-0090.json
Credits
- Neeraj Murarka
Feedback
See anything missing or incorrect?
Suggest an edit to this report.