CVE-2022-23507

CVSS V2 None CVSS V3 None
Description
Tendermint is a high-performance blockchain consensus engine for Byzantine fault tolerant applications. Versions prior to 0.28.0 contain a potential attack via Improper Verification of Cryptographic Signature, affecting anyone using the tendermint-light-client and related packages to perform light client verification (e.g. IBC-rs, Hermes). The light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. This issue is patched in version 0.28.0. There are no workarounds.
Overview
  • CVE ID
  • CVE-2022-23507
  • Assigner
  • security-advisories@github.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2022-12-15T19:15:16
  • Last Modified Date
  • 2022-12-20T16:14:56
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:tendermint-light-client-js_project:tendermint-light-client-js:*:*:*:*:rust:*:*:* 1 OR 0.28.0
cpe:2.3:a:tendermint-light-client-verifier_project:tendermint-light-client-verifier:*:*:*:*:*:rust:*:* 1 OR 0.28.0
cpe:2.3:a:tendermint-light-client_project:tendermint-light-client:*:*:*:*:rust:*:*:* 1 OR 0.28.0
History
Created Old Value New Value Data Type Notes
2022-12-15 19:16:03 Added to TrackCVE
2022-12-15 20:15:17 2022-12-15T19:15:16.723 2022-12-15T19:15:16 CVE Published Date updated
2022-12-15 20:15:17 2022-12-15T19:56:28 CVE Modified Date updated
2022-12-15 20:15:17 Received Awaiting Analysis Vulnerability Status updated
2022-12-18 09:30:13 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2022-12-21 07:02:29 2022-12-20T16:14:56 CVE Modified Date updated
2022-12-21 07:02:29 Undergoing Analysis Analyzed Vulnerability Status updated
2022-12-21 07:02:31 CPE Information updated