Race Condition Affecting chia-blockchain package, versions [,1.4.0)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-CHIABLOCKCHAIN-5840630
- published 14 Aug 2023
- disclosed 1 Aug 2023
- credit mariano54
How to fix?
Upgrade chia-blockchain
to version 1.4.0 or higher.
Overview
chia-blockchain is a Chia blockchain full node, farmer, timelord, and wallet.
Affected versions of this package are vulnerable to Race Condition due to inconsistent checks which can lead to failed validation and fallback to an empty block.
References
CVSS Scores
version 3.1