Skip to content
Cosmopediaby Unity Nodes
DiscussionsSecurityVulnerability Coordination Retrospective: Tendermint Core Security Advisory Syringa, 2020-07-02Forum ↗

Vulnerability Coordination Retrospective: Tendermint Core Security Advisory Syringa, 2020-07-02

Security1 posts1,781 views1 likesLast activity Jul 2020
TE
tessrOP
Jul 2020 1

On June 28, 2020, the Tendermint Core team identified a pair of bugs which, when exploited, could be used to halt networks running Tendermint Core 0.33 or later. On July 2, 2020, at 14:00 UTC, Tendermint Core version 0.33.6 was released with patches for these vulnerabilities. Version 0.38.5 of the Cosmos SDK was released shortly thereafter. Impacts from these vulnerabilities were initially reported on May 31, 2020, by @njmurarka from Bluzelle Networks; and the Bluzelle team’s ongoing reports were instrumental in identifying and fixing these issues. Gaia was not impacted by these vulnerabilities. The triage, remediation and communication processes were a collaborative effort by employees of All In Bits GmbH, Informal Systems Inc., and Interchain GmbH. The Bugs Two of the major changes introduced in Tendermint 0.33 were: • New commit verification logic to support the forthcoming light client • New commit structure to deduplicate data and dramatically reduce the size of commits However, each change also introduced a bug to the preexisting verification flows. Denial of Service Tendermint versions between 0.33.0 and 0.33.5, inclusive, allowed block proposers to…

Excerpt (1196 of 7915 characters). Read the whole post on the forum ↗

← Back to Discussions