Headline
GHSA-7c94-gvvj-r3mg: cheqd-node affected by Inter-blockchain Communication (IBC) protocol "Huckleberry" vulnerability
Impact
This vulnerability affects the ibc-go
package for those running full nodes, dubbed “Huckleberry”. According to their advisory:
This issue is low-severity in general, and it has a low impact and likelihood of exploitation. Depending on how a full node is architected, this issue could potentially yield a high or critical severity vulnerability.
There is no vulnerability in the DID/resource modules for cheqd-node.
Patches
Node operators are requested to upgrade to cheqd-node v1.4.2. This is a non-state breaking release, and does not require a coordinated upgrade across all node operators.
Workarounds
No. Node operators are recommended to upgrade to the latest release version.
References
Package
gomod github.com/cheqd/cheqd-node (Go)
Affected versions
< 1.4.2
Patched versions
1.4.2
Description
Impact
This vulnerability affects the ibc-go package for those running full nodes, dubbed "Huckleberry". According to their advisory:
This issue is low-severity in general, and it has a low impact and likelihood of exploitation. Depending on how a full node is architected, this issue could potentially yield a high or critical severity vulnerability.
There is no vulnerability in the DID/resource modules for cheqd-node.
Patches
Node operators are requested to upgrade to cheqd-node v1.4.2. This is a non-state breaking release, and does not require a coordinated upgrade across all node operators.
Workarounds
No. Node operators are recommended to upgrade to the latest release version.
References
- “Huckleberry” IBC security advisory
- ibc-go v6.1.1 release notes
References
- GHSA-7c94-gvvj-r3mg
- cheqd/cheqd-node@f325f5f
- https://forum.cosmos.network/t/ibc-security-advisory-huckleberry/10731
- https://github.com/cheqd/cheqd-node/releases/tag/v1.4.2
- https://github.com/cosmos/ibc-go/releases/tag/v6.1.1
ankurdotb published to cheqd/cheqd-node
May 27, 2023
Published to the GitHub Advisory Database
Jun 5, 2023
Reviewed
Jun 5, 2023
Last updated
Jun 5, 2023