chia-blockchain@1.0b2 vulnerabilities

Chia blockchain full node, farmer, timelord, and wallet.

  • latest version

    2.5.4

  • latest non vulnerable version

  • first published

    5 years ago

  • latest version published

    1 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the chia-blockchain package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Denial of Service (DoS)

    chia-blockchain is a Chia blockchain full node, farmer, timelord, and wallet.

    Affected versions of this package are vulnerable to Denial of Service (DoS) due to the token management process. An attacker can inflate the total amount of the token to an arbitrary extent by manipulating the issuance rules.

    How to fix Denial of Service (DoS)?

    Upgrade chia-blockchain to version 1.5.0 or higher.

    [,1.5.0)
    • H
    Race Condition

    chia-blockchain is a Chia blockchain full node, farmer, timelord, and wallet.

    Affected versions of this package are vulnerable to Race Condition due to inconsistent checks which can lead to failed validation and fallback to an empty block.

    How to fix Race Condition?

    Upgrade chia-blockchain to version 1.4.0 or higher.

    [,1.4.0)
    • L
    Denial of Service (DoS)

    chia-blockchain is a Chia blockchain full node, farmer, timelord, and wallet.

    Affected versions of this package are vulnerable to Denial of Service (DoS). DDoS attacks could be possible due to no rate limiting for the full node.

    How to fix Denial of Service (DoS)?

    Upgrade chia-blockchain to version 1.0rc6 or higher.

    [,1.0rc6)