Skip to content

x/vulndb: potential Go vuln in github.com/cosmos/cosmos-sdk: GHSA-8wcc-m6j2-qxvm #3339

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
GoVulnBot opened this issue Dec 16, 2024 · 2 comments

Comments

@GoVulnBot
Copy link

Advisory GHSA-8wcc-m6j2-qxvm references a vulnerability in the following Go modules:

Module
github.com/cosmos/cosmos-sdk

Description:

Summary

ASA-2024-0012

Name: ASA-2024-0012, Transaction decoding may result in a stack overflow
Component: Cosmos SDK
Criticality: High (Considerable Impact, and Possible Likelihood per ACMv1.2)
Affected versions: cosmos-sdk versions <= v0.50.10, <= v0.47.14
Affected users: Chain Builders + Maintainers, Validators, node operators

ASA-2024-0013

Name: ASA-2024-0013: CosmosSDK: Transaction decoding may result in resource exhaustion
Component: Cosmos SDK
Criticality: High (Considerable Impact, ...

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/cosmos/cosmos-sdk
      versions:
        - fixed: 0.47.15
        - introduced: 0.50.0-alpha.0
        - fixed: 0.50.11
      vulnerable_at: 0.50.10
summary: |-
    ASA-2024-0012, ASA-2024-0013: CosmosSDK: Transaction decoding may result in a
    stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk
ghsas:
    - GHSA-8wcc-m6j2-qxvm
references:
    - advisory: https://github.com/advisories/GHSA-8wcc-m6j2-qxvm
    - advisory: https://github.com/cosmos/cosmos-sdk/security/advisories/GHSA-8wcc-m6j2-qxvm
    - fix: https://github.com/cosmos/cosmos-sdk/commit/c6b1bdcd5628e3e425a3f02881d3c7db1d7af653
    - web: https://github.com/cosmos/cosmos-sdk/releases/tag/v0.47.15
    - web: https://github.com/cosmos/cosmos-sdk/releases/tag/v0.50.11
source:
    id: GHSA-8wcc-m6j2-qxvm
    created: 2024-12-16T20:03:17.990893449Z
review_status: UNREVIEWED

@gopherbot
Copy link
Contributor

Change https://go.dev/cl/636718 mentions this issue: data/reports: add GO-2024-3339

gopherbot pushed a commit that referenced this issue Dec 18, 2024
  - data/reports/GO-2024-3339.yaml

Updates #3339

Change-Id: If0974c6d20644470348c744d888f87ce32ba8042
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/636718
Reviewed-by: Damien Neil <[email protected]>
Auto-Submit: Tatiana Bradley <[email protected]>
LUCI-TryBot-Result: Go LUCI <[email protected]>
@gopherbot
Copy link
Contributor

Change https://go.dev/cl/637980 mentions this issue: data/reports: review 2 reports

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants