You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
See doc/triage.md for instructions on how to triage this report.
modules:
- module: TODO
versions:
- fixed: 0.4.1
packages:
- package: github.com/cosmos/ethermint/rpc/namespaces/eth
- module: TODO
versions:
- fixed: 0.4.1
packages:
- package: github.com/cosmos/ethermint
description: Cosmos Network Ethermint <= v0.4.0 is affected by a cross-chain transaction
replay vulnerability in the EVM module. Since ethermint uses the same chainIDEpoch
and signature schemes with ethereum for compatibility, a verified signature in
ethereum is still valid in ethermint with the same msg content and chainIDEpoch,
which enables "cross-chain transaction replay" attack.
cves:
- CVE-2021-25835
ghsas:
- GHSA-x5f3-qmwj-4f84
The text was updated successfully, but these errors were encountered:
In GitHub Security Advisory GHSA-x5f3-qmwj-4f84, there is a vulnerability in the following Go packages or modules:
Cross references:
See doc/triage.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: