Vulnerability Coordination Retrospective: Tendermint Core Security Advisory Syringa, 2020-07-02
On June 28, 2020, the Tendermint Core team identified a pair of bugs which, when exploited, could be used to halt networks running Tendermint Core 0.33 or later. On July 2, 2020, at 14:00 UTC, Tendermint Core version 0.33.6 was released with patches for these vulnerabilities. Version 0.38.5 of the Cosmos SDK was released shortly thereafter. Impacts from these vulnerabilities were initially reported on May 31, 2020, by @njmurarka from Bluzelle Networks; and the Bluzelle team’s ongoing reports were instrumental in identifying and fixing these issues. Gaia was not impacted by these vulnerabilities. The triage, remediation and communication processes were a collaborative effort by employees of All In Bits GmbH, Informal Systems Inc., and Interchain GmbH. The Bugs Two of the major changes introduced in Tendermint 0.33 were: • New commit verification logic to support the forthcoming light client • New commit structure to deduplicate data and dramatically reduce the size of commits However, each change also introduced a bug to the preexisting verification flows. Denial of Service Tendermint versions between 0.33.0 and 0.33.5, inclusive, allowed block proposers to…
Excerpt (1196 of 7915 characters). Read the whole post on the forum ↗