Vulnerability Report: GO-2024-2471
- GHSA-qr8r-m495-7hc4
- Affects: github.com/cometbft/cometbft
- Published: Jan 23, 2024
A vulnerability in CometBFT’s validation logic for VoteExtensionsEnableHeight can result in a chain halt when triggered through a governance parameter change proposal on an ABCI2 Application Chain. If a parameter change proposal including a VoteExtensionsEnableHeight modification is passed, nodes running the affected versions may panic, halting the network.
For detailed information about this vulnerability, visit https://github.com/cometbft/cometbft/security/advisories/GHSA-qr8r-m495-7hc4.
Affected Packages
-
PathVersionsSymbols
-
from v0.38.0 before v0.38.3
Aliases
References
- https://github.com/cometbft/cometbft/security/advisories/GHSA-qr8r-m495-7hc4
- https://github.com/cometbft/cometbft/commit/5fbc97378b94b0945febe9549399e7c9c5df13ed
- https://vuln.go.dev/ID/GO-2024-2471.json
Credits
- @dongsam
Feedback
See anything missing or incorrect?
Suggest an edit to this report.