grandpa-verifier
Activity
- Latest release
- 1mo ago
- Total releases
- 13
- Cadence
- ~2 months
- Last 12 months
- 4
Details
- License
- Apache-2.0
- First release
- Sep 19, 2024
| Version | Released | |
|---|---|---|
2606.0.0
unknown
|
2606.0.0
unknown
Dependencies (18)
+ 10 more |
|
2512.1.0
unknown
|
2512.1.0
unknown
Dependencies (18)
+ 10 more |
|
2512.0.0
unknown
yanked
|
2512.0.0
unknown
yanked
Dependencies (17)
+ 9 more |
|
2.2.0
unknown
yanked
|
2.2.0
unknown
yanked
Dependencies (16)
+ 8 more |
|
2506.1.0
unknown
yanked
|
2506.1.0
unknown
yanked
Dependencies (17)
+ 9 more |
|
2506.0.0
unknown
yanked
|
2506.0.0
unknown
yanked
Dependencies (17)
+ 9 more |
|
2.1.0
unknown
yanked
|
2.1.0
unknown
yanked
Dependencies (16)
+ 8 more |
|
2.0.0
unknown
yanked
|
2.0.0
unknown
yanked
Dependencies (16)
+ 8 more |
|
1.0.0
unknown
yanked
|
1.0.0
unknown
yanked
Dependencies (16)
+ 8 more |
|
0.2.0
unknown
yanked
|
0.2.0
unknown
yanked
Dependencies (17)
+ 9 more |
|
0.1.2
unknown
yanked
|
0.1.2
unknown
yanked
Dependencies (25)
+ 17 more |
|
0.1.1
unknown
yanked
1 CVE
CVE-2025-24800
GHSA-wwx5-gpgr-vxr7
Jan 28, 2025
ismp-grandpa crate accepted incorrect signatures
Critical
Network
Low
None
None
A critical vulnerability was discovered in the DescriptionThe vulnerability manifests as a verifer that only accepts incorrect signatures of Grandpa precommits and was introduced in this specific commit. Perhaps due to unfamiliarity with core substrate APIs. The This vulnerability remained undetected even with integration tests, as the prover was also misconfigured to initialize the Grandpa verifier with the incorrect authority But even more devastatingly, the verifier will also accept malicious GRANDPA signatures for any precommit message. This vulnerability has been fixed in this commit and a patch release has been published. ImpactThis could be used to steal funds or compromise other kinds of cross-chain applications. PatchesThis vulnerability has been fixed in the latest version of RecommendationsUsers who rely on the compromised versions must upgrade immediately, as all vulnerable versions of the crate has been yanked. Fixed in
0.1.2
References
Updated Jan 28, 2025 · Source: OSV.dev |
0.1.1
unknown
yanked
Dependencies (25)
+ 17 more |
|
0.1.0
unknown
yanked
1 CVE
CVE-2025-24800
GHSA-wwx5-gpgr-vxr7
Jan 28, 2025
ismp-grandpa crate accepted incorrect signatures
Critical
Network
Low
None
None
A critical vulnerability was discovered in the DescriptionThe vulnerability manifests as a verifer that only accepts incorrect signatures of Grandpa precommits and was introduced in this specific commit. Perhaps due to unfamiliarity with core substrate APIs. The This vulnerability remained undetected even with integration tests, as the prover was also misconfigured to initialize the Grandpa verifier with the incorrect authority But even more devastatingly, the verifier will also accept malicious GRANDPA signatures for any precommit message. This vulnerability has been fixed in this commit and a patch release has been published. ImpactThis could be used to steal funds or compromise other kinds of cross-chain applications. PatchesThis vulnerability has been fixed in the latest version of RecommendationsUsers who rely on the compromised versions must upgrade immediately, as all vulnerable versions of the crate has been yanked. Fixed in
0.1.2
References
Updated Jan 28, 2025 · Source: OSV.dev |
0.1.0
unknown
yanked
Dependencies (25)
+ 17 more |