Hydra 在提交验证器上提交的 UTxO 和初始验证器上的 UTxO 可以被任何人任意使用 (CVE-2023-38701)

admin 2023-11-29 20:52:26 Ali_nvd 来源:ZONE.CI 全球网 0 阅读模式
Hydra 在提交验证器上提交的 UTxO 和初始验证器上的 UTxO 可以被任何人任意使用 (CVE-2023-38701)

CVE编号

CVE-2023-38701

利用情况

暂无

补丁情况

N/A

披露时间

2023-10-05
漏洞描述
Hydra is the layer-two scalability solution for Cardano. Users of the Hydra head protocol send the UTxOs they wish to commit into the Hydra head first to the `commit` validator, where they remain until they are either collected into the `head` validator or the protocol initialisation is aborted and the value in the committed UTxOs is returned to the users who committed them. Prior to version 0.12.0, the `commit` validator contains a flawed check when the `ViaAbort` redeemer is used, which allows any user to spend any UTxO which is at the validator arbitrarily, meaning an attacker can steal the funds that users are trying to commit into the head validator. The intended behavior is that the funds must be returned to the user which committed the funds and can only be performed by a participant of the head. The `initial` validator also is similarly affected as the same flawed check is performed for the `ViaAbort` redeemer. Due to this issue, an attacker can steal any funds that user's try to commit into a Hydra head. Also, an attacker can prevent any Hydra head from being successfully opened. It does not allow an attacker to take funds which have been successfully collected into and currently reside in the `head` validator. Version 0.12.0 contains a fix for this issue.
解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接
https://github.com/input-output-hk/hydra/blob/master/CHANGELOG.md
https://github.com/input-output-hk/hydra/blob/master/hydra-plutus/src/Hydra/C...
https://github.com/input-output-hk/hydra/blob/master/hydra-plutus/src/Hydra/C...
https://github.com/input-output-hk/hydra/security/advisories/GHSA-6x9v-7x5r-w8w6
受影响软件情况
# 类型 厂商 产品 版本 影响面
1
运行在以下环境
应用 iohk hydra * Up to (excluding) 0.12.0
CVSS3评分 9.1
  • 攻击路径 网络
  • 攻击复杂度 低
  • 权限要求 无
  • 影响范围 未更改
  • 用户交互 无
  • 可用性 高
  • 保密性 无
  • 完整性 高
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CWE-ID 漏洞类型
CWE-20 输入验证不恰当
NVD-CWE-noinfo
- avd.aliyun.com
weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
N/A Ali_nvd

N/A

N/ACVE编号 CVE-2024-9120利用情况 暂无补丁情况 N/A披露时间 2024-09-23漏洞描述Use after free in Dawn
评论:0   参与:  0