VDB
Sign up
LOW

GHSA-7c94-gvvj-r3mg

cheqd-node affected by Inter-blockchain Communication (IBC) protocol "Huckleberry" vulnerability

Quick fix

GHSA-7c94-gvvj-r3mg — github.com/cheqd/cheqd-node: upgrade to the fixed version with the command below.

go get github.com/cheqd/cheqd-node@v1.4.2

Details

### Impact This vulnerability affects the [`ibc-go` package for those running full nodes, dubbed "Huckleberry"](https://forum.cosmos.network/t/ibc-security-advisory-huckleberry/10731). According to their advisory:

> This issue is low-severity in general, and it has a low impact and likelihood of exploitation. Depending on how a full node is architected, this issue could potentially yield a high or critical severity vulnerability.

There is no vulnerability in the DID/resource modules for cheqd-node.

### Patches Node operators are requested to upgrade to [cheqd-node v1.4.2](https://github.com/cheqd/cheqd-node/releases/tag/v1.4.2). This is a non-state breaking release, and does not require a coordinated upgrade across all node operators.

### Workarounds No. Node operators are recommended to upgrade to the latest release version.

### References - ["Huckleberry" IBC security advisory](https://forum.cosmos.network/t/ibc-security-advisory-huckleberry/10731) - [`ibc-go` v6.1.1 release notes](https://github.com/cosmos/ibc-go/releases/tag/v6.1.1)

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/cheqd/cheqd-node
Introduced in: 0Fixed in: 1.4.2
Fixgo get github.com/cheqd/cheqd-node@v1.4.2

References