GO-2022-1052

    Dashboard / Vulnerabilities / GO-2022-1052

    GO-2022-1052

    Published: 14 Oct 2022Last Modified: 20 May 2024

    Summary: Uncontrolled resource consumption during consensus in github.com/tendermint/tendermint

    Details: Mishandling of timestamps during consensus process can cause a denial of service. While reaching consensus, different tendermint nodes can observe a different timestamp for a consensus evidence. This mismatch can cause the evidence to be invalid, upon which the node producing the evidence will be asked to generate a new evidence. This new evidence will be the same, which means it will again be rejected by other nodes involved in the consensus. This loop will continue until the peer nodes decide to disconnect from the node producing the evidence.

    Affected packages

    Package

    Name: github.com/tendermint/tendermint

    Purl: pkg:golang/github.com/tendermint/tendermint

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.34.0
    Fixed -0.34.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GO-2022-1052 | CVE-DB