Improper Input Validation Affecting github.com/cometbft/cometbft/types package, versions >=0.38.0 <0.38.3
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-GOLANG-GITHUBCOMCOMETBFTCOMETBFTTYPES-6182929
- published 21 Jan 2024
- disclosed 19 Jan 2024
- credit Dongsam
How to fix?
Upgrade github.com/cometbft/cometbft/types
to version 0.38.3 or higher.
Overview
Affected versions of this package are vulnerable to Improper Input Validation due to improper validation of the VoteExtensionsEnableHeight
parameter. An attacker can cause a network halt by triggering a governance parameter change proposal on an ABCI2 Application Chain that includes a modification to VoteExtensionsEnableHeight
.
References
CVSS Scores
version 3.1