Vulnerability Report: GO-2024-3259
- GHSA-p7mv-53f2-4cwj
- Affects: github.com/cometbft/cometbft
- Published: Nov 20, 2024
- Modified: Dec 12, 2024
CometBFT Vote Extensions: Panic when receiving a Pre-commit with an invalid data in github.com/cometbft/cometbft
For detailed information about this vulnerability, visit https://github.com/cometbft/cometbft/security/advisories/GHSA-p7mv-53f2-4cwj.
Affected Packages
-
PathGo VersionsSymbols
-
from v0.38.0 before v0.38.15
Aliases
References
- https://github.com/cometbft/cometbft/security/advisories/GHSA-p7mv-53f2-4cwj
- https://docs.cometbft.com/v0.38/spec/abci/abci++_basic_concepts
- https://github.com/cometbft/cometbft/releases/tag/v0.38.15
- https://github.com/cometbft/cometbft/commit/17d3bb66664cab6d6798c17e27198e15bbac1905
- https://vuln.go.dev/ID/GO-2024-3259.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.