Skip to content

Authz Module Non-Determinism

High
aaronc published GHSA-2p6r-37p9-89p2 Oct 20, 2021

Package

No package listed

Affected versions

0.44.x

Patched versions

None

Description

Impact

Consensus failure for 0.43.x and 0.44.{0,1} users.
Funds and balances are safe.

Patches

0.44.2

Workarounds

Manually patch the code.


Full details posted in https://forum.cosmos.network/t/cosmos-sdk-vulnerability-retrospective-security-advisory-jackfruit-october-12-2021/5349.

Severity

High

CVE ID

CVE-2021-41135

Weaknesses

No CWEs

Credits