Tendermint Core Vulnerability Retrospective: Security Advisory Mulberry, January 19, 2021
On January 8, 2021, the team at Crypto.com reported a medium security vulnerability (“Denial of Service 1”) to the team via [email protected] . On January 12, the Tendermint Core team released v0.34.2, with a patch for Denial of Service 1. On January 13, further testing revealed an additional vulnerability (“Denial of Service 2”). We determined this vulnerability to be high severity, and followed the process outlined in our security policy . On January 19 at 16:00 UTC, we released Tendermint Core v0.34.3, which included a patch for Denial of Service 2. Both vulnerabilities impacted Tendermint Core versions 0.34.0 and later, Cosmos SDK v0.40.0, and Gaia v3.0.0. The current Cosmos Hub was unaffected. The Bugs The vulnerabilities that were reported demonstrated a pair of flaws in Tendermint Core’s evidence handling code. When exploited by an attacker double-signing transactions, these vulnerabilities could cause a remote panic. This means that an attacker with access to a large number of validators could perform a large denial of service attack; however, most applications are configured to severely punish double-signing such that this kind of attack would be extremely…
Excerpt (1197 of 7802 characters). Read the whole post on the forum ↗
Hi @tessr, I am new to the ecosystem and wanted to make sure I follow all the security feeds available.
I signed up for the Tendermint Security mailing list and for notifications on this forum for the Security channel, but was wondering if there were other security sources I should follow. Thanks PW