tendermint-light-client-js
Activity
- Latest release
- 1y ago
- Total releases
- 46
- Cadence
- ~26 days
- Last 12 months
- 0
Details
- License
- Apache-2.0
- First release
- Apr 07, 2021
| Version | Released | |
|---|---|---|
0.40.4
unknown
|
0.40.4
unknown
Dependencies (9)
+ 1 more |
|
0.40.3
unknown
|
0.40.3
unknown
Dependencies (9)
+ 1 more |
|
0.40.2
unknown
|
0.40.2
unknown
Dependencies (9)
+ 1 more |
|
0.40.1
unknown
|
0.40.1
unknown
Dependencies (9)
+ 1 more |
|
0.40.0
unknown
|
0.40.0
unknown
Dependencies (8)
|
|
0.39.1
unknown
|
0.39.1
unknown
Dependencies (8)
|
|
0.39.0
unknown
|
0.39.0
unknown
Dependencies (8)
|
|
0.38.1
unknown
|
0.38.1
unknown
Dependencies (8)
|
|
0.38.0
unknown
|
0.38.0
unknown
Dependencies (8)
|
|
0.37.0
unknown
|
0.37.0
unknown
Dependencies (8)
|
|
0.36.0
unknown
|
0.36.0
unknown
Dependencies (8)
|
|
0.35.0
unknown
|
0.35.0
unknown
Dependencies (8)
|
|
0.34.1
unknown
|
0.34.1
unknown
Dependencies (8)
|
|
0.34.0
unknown
|
0.34.0
unknown
Dependencies (8)
|
|
0.33.2
unknown
|
0.33.2
unknown
Dependencies (8)
|
|
0.33.1
unknown
|
0.33.1
unknown
Dependencies (8)
|
|
0.33.0
unknown
|
0.33.0
unknown
Dependencies (8)
|
|
0.32.2
unknown
|
0.32.2
unknown
Dependencies (8)
|
|
0.32.0
unknown
|
0.32.0
unknown
Dependencies (8)
|
|
0.31.1
unknown
|
0.31.1
unknown
Dependencies (8)
|
|
0.31.0
unknown
|
0.31.0
unknown
Dependencies (8)
|
|
0.30.0
unknown
|
0.30.0
unknown
Dependencies (8)
|
|
0.29.1
unknown
|
0.29.1
unknown
Dependencies (8)
|
|
0.29.0
unknown
|
0.29.0
unknown
Dependencies (8)
|
|
0.28.0
unknown
|
0.28.0
unknown
Dependencies (8)
|
|
0.28.0-pre.1
unknown
1 CVE
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.28.0-pre.1
unknown
Dependencies (8)
|
|
0.27.0
unknown
1 CVE
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.27.0
unknown
Dependencies (8)
|
|
0.26.0
unknown
1 CVE
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.26.0
unknown
Dependencies (8)
|
|
0.25.0
unknown
1 CVE
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.25.0
unknown
Dependencies (8)
|
|
0.23.9
unknown
1 CVE
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.23.9
unknown
Dependencies (9)
+ 1 more |
|
0.23.8
unknown
1 CVE
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.23.8
unknown
Dependencies (9)
+ 1 more |
|
0.23.8-pre.1
unknown
1 CVE
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.23.8-pre.1
unknown
Dependencies (9)
+ 1 more |
|
0.24.0-pre.2
unknown
1 CVE
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.24.0-pre.2
unknown
Dependencies (9)
+ 1 more |
|
0.23.7
unknown
1 CVE
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.23.7
unknown
Dependencies (9)
+ 1 more |
|
0.23.6
unknown
1 CVE
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.23.6
unknown
Dependencies (9)
+ 1 more |
|
0.24.0-pre.1
unknown
1 CVE
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.24.0-pre.1
unknown
Dependencies (9)
+ 1 more |
|
0.23.5
unknown
1 CVE
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.23.5
unknown
Dependencies (9)
+ 1 more |
|
0.23.4
unknown
1 CVE
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.23.4
unknown
Dependencies (9)
+ 1 more |
|
0.23.3
unknown
1 CVE
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.23.3
unknown
Dependencies (9)
+ 1 more |
|
0.23.2
unknown
1 CVE
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.23.2
unknown
Dependencies (9)
+ 1 more |
|
0.23.1
unknown
1 CVE
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.23.1
unknown
Dependencies (9)
+ 1 more |
|
0.23.0
unknown
1 CVE
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.23.0
unknown
Dependencies (9)
+ 1 more |
|
0.22.0
unknown
1 CVE
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.22.0
unknown
Dependencies (9)
+ 1 more |
|
0.21.0
unknown
1 CVE
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.21.0
unknown
Dependencies (9)
+ 1 more |
|
0.20.0
unknown
1 CVE
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.20.0
unknown
Dependencies (9)
+ 1 more |
|
0.19.0
unknown
1 CVE
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.19.0
unknown
Dependencies (9)
+ 1 more |