Audit Dashboard
Audit Dashboard
Target Summary
- Name: Interblockchain Communication Protocol
- Code Version: 6cbbe0d4ef90f886dfc356979b89979ddfcd00d8
- Specification Version: 7e6978ae551bbed439c69178184dea0a25d0e747
- Type: Implementation
- Platform: Golang
Engagement Summary
- Dates: October 26 through November 19 2020
- Method: Whitebox
- Employees Engaged: 4
- Time Spent: 8 person-weeks
Vulnerability Summary
| Issue Type | # | Finding |
|---|---|---|
| Total High-Severity Issues | 4 | IF-IBC-06, IF-IBC-09, IF-IBC-10, IF-IBC-14 |
| Total Medium-Severity Issues | 5 | IF-IBC-01, IF-IBC-02, IF-IBC-03, IF-IBC-08, IF-IBC-11 |
| Total Low-Severity Issues | 2 | IF-IBC-04, IF-IBC-07 |
| Total Informative-Severity Issues | 3 | IF-IBC-05, IF-IBC-12, IF-IBC-13 |
| Total | 14 |
Category Breakdown
| Finding Type | # |
|---|---|
| Specification deviation | 6 |
| Protocol/Implementation bug | 3 |
| Implementation bug | 2 |
| Specification restructuring proposals | 1 |
| Code restructuring proposals | 2 |
| Total | 14 |
Severity Categories
| Severity | Description |
|---|---|
| Informational | The issue does not pose an immediate risk (it is subjective in nature); they are typically suggestions around best practices or readability |
| Low | The issue is objective in nature, but the security risk is relatively small or does not represent security vulnerability |
| Medium | The issue is a security vulnerability that may not be directly exploitable or may require certain complex conditions in order to be exploited |
| High | The issue is exploitable security vulnerability |