diff --git a/advisories/github-reviewed/2023/03/GHSA-56r9-72vx-q989/GHSA-56r9-72vx-q989.json b/advisories/github-reviewed/2023/03/GHSA-56r9-72vx-q989/GHSA-56r9-72vx-q989.json index 0a1922da2bd..e153e9053d0 100644 --- a/advisories/github-reviewed/2023/03/GHSA-56r9-72vx-q989/GHSA-56r9-72vx-q989.json +++ b/advisories/github-reviewed/2023/03/GHSA-56r9-72vx-q989/GHSA-56r9-72vx-q989.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-56r9-72vx-q989", - "modified": "2023-03-28T02:24:32Z", + "modified": "2024-04-19T16:22:09Z", "published": "2023-03-23T21:30:18Z", "aliases": [ "CVE-2023-28330" @@ -101,6 +101,10 @@ "type": "WEB", "url": "https://github.com/moodle/moodle/commit/493205b6b280633bcbc49d2eaf4f61a52252c26c" }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2179412" + }, { "type": "WEB", "url": "https://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-77204" @@ -109,6 +113,10 @@ "type": "PACKAGE", "url": "https://github.com/moodle/moodle" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QZN34VSF4HTCW3C3ZP2OZYSLYUKADPF" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3QZN34VSF4HTCW3C3ZP2OZYSLYUKADPF" diff --git a/advisories/github-reviewed/2023/03/GHSA-77jm-f3vj-xvx2/GHSA-77jm-f3vj-xvx2.json b/advisories/github-reviewed/2023/03/GHSA-77jm-f3vj-xvx2/GHSA-77jm-f3vj-xvx2.json index c8c6c291357..9a0b653f846 100644 --- a/advisories/github-reviewed/2023/03/GHSA-77jm-f3vj-xvx2/GHSA-77jm-f3vj-xvx2.json +++ b/advisories/github-reviewed/2023/03/GHSA-77jm-f3vj-xvx2/GHSA-77jm-f3vj-xvx2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-77jm-f3vj-xvx2", - "modified": "2023-03-28T02:40:54Z", + "modified": "2024-04-19T16:22:07Z", "published": "2023-03-23T21:30:18Z", "aliases": [ "CVE-2023-28331" @@ -101,6 +101,10 @@ "type": "WEB", "url": "https://github.com/moodle/moodle/commit/1899e0397350c4c2bb3e73773981f66f16f8f2fc" }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2179418" + }, { "type": "WEB", "url": "https://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=1899e0397350c4c2bb3e73773981f66f16f8f2fc" @@ -109,6 +113,10 @@ "type": "PACKAGE", "url": "https://github.com/moodle/moodle" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QZN34VSF4HTCW3C3ZP2OZYSLYUKADPF" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3QZN34VSF4HTCW3C3ZP2OZYSLYUKADPF" diff --git a/advisories/github-reviewed/2023/03/GHSA-9f45-9qrw-pp4v/GHSA-9f45-9qrw-pp4v.json b/advisories/github-reviewed/2023/03/GHSA-9f45-9qrw-pp4v/GHSA-9f45-9qrw-pp4v.json index 574f7baa6f0..5fe3dbba327 100644 --- a/advisories/github-reviewed/2023/03/GHSA-9f45-9qrw-pp4v/GHSA-9f45-9qrw-pp4v.json +++ b/advisories/github-reviewed/2023/03/GHSA-9f45-9qrw-pp4v/GHSA-9f45-9qrw-pp4v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9f45-9qrw-pp4v", - "modified": "2023-03-29T19:10:48Z", + "modified": "2024-04-19T16:22:05Z", "published": "2023-03-23T21:30:18Z", "aliases": [ "CVE-2023-28332" @@ -101,6 +101,10 @@ "type": "WEB", "url": "https://github.com/moodle/moodle/commit/9f178c1f816e78ec024ab16a10192c81305b2624" }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2179419" + }, { "type": "WEB", "url": "https://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=9f178c1f816e78ec024ab16a10192c81305b2624" @@ -109,6 +113,10 @@ "type": "PACKAGE", "url": "https://github.com/moodle/moodle" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QZN34VSF4HTCW3C3ZP2OZYSLYUKADPF" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3QZN34VSF4HTCW3C3ZP2OZYSLYUKADPF" diff --git a/advisories/github-reviewed/2023/03/GHSA-prjm-2fj2-787f/GHSA-prjm-2fj2-787f.json b/advisories/github-reviewed/2023/03/GHSA-prjm-2fj2-787f/GHSA-prjm-2fj2-787f.json index 70eb8c1b8c3..878fe5d8dd1 100644 --- a/advisories/github-reviewed/2023/03/GHSA-prjm-2fj2-787f/GHSA-prjm-2fj2-787f.json +++ b/advisories/github-reviewed/2023/03/GHSA-prjm-2fj2-787f/GHSA-prjm-2fj2-787f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-prjm-2fj2-787f", - "modified": "2023-04-03T20:55:33Z", + "modified": "2024-04-19T16:21:33Z", "published": "2023-03-23T21:30:17Z", "aliases": [ "CVE-2023-28336" @@ -101,6 +101,10 @@ "type": "WEB", "url": "https://github.com/moodle/moodle/commit/a931a7f8cec3657827268837b27962a13817ca2b" }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2179426" + }, { "type": "WEB", "url": "https://git.moodle.org/gw?p=moodle.git;a=commit;h=a931a7f8cec3657827268837b27962a13817ca2b" @@ -109,6 +113,10 @@ "type": "PACKAGE", "url": "https://github.com/moodle/moodle" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QZN34VSF4HTCW3C3ZP2OZYSLYUKADPF" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3QZN34VSF4HTCW3C3ZP2OZYSLYUKADPF" diff --git a/advisories/github-reviewed/2023/03/GHSA-q2x3-2f9g-h559/GHSA-q2x3-2f9g-h559.json b/advisories/github-reviewed/2023/03/GHSA-q2x3-2f9g-h559/GHSA-q2x3-2f9g-h559.json index 9dd0412d518..7e3d471f3be 100644 --- a/advisories/github-reviewed/2023/03/GHSA-q2x3-2f9g-h559/GHSA-q2x3-2f9g-h559.json +++ b/advisories/github-reviewed/2023/03/GHSA-q2x3-2f9g-h559/GHSA-q2x3-2f9g-h559.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q2x3-2f9g-h559", - "modified": "2023-03-31T16:09:20Z", + "modified": "2024-04-19T16:22:00Z", "published": "2023-03-23T21:30:18Z", "aliases": [ "CVE-2023-28333" @@ -101,6 +101,10 @@ "type": "WEB", "url": "https://github.com/moodle/moodle/commit/128c0c21607a71f411611a0104b2a8c858dd6fca" }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2179422" + }, { "type": "WEB", "url": "https://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=128c0c21607a71f411611a0104b2a8c858dd6fca" @@ -109,6 +113,10 @@ "type": "PACKAGE", "url": "https://github.com/moodle/moodle" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QZN34VSF4HTCW3C3ZP2OZYSLYUKADPF" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3QZN34VSF4HTCW3C3ZP2OZYSLYUKADPF" diff --git a/advisories/github-reviewed/2023/05/GHSA-22gj-8qj2-fj46/GHSA-22gj-8qj2-fj46.json b/advisories/github-reviewed/2023/05/GHSA-22gj-8qj2-fj46/GHSA-22gj-8qj2-fj46.json index c79ba6f8e0d..0e8b0a16397 100644 --- a/advisories/github-reviewed/2023/05/GHSA-22gj-8qj2-fj46/GHSA-22gj-8qj2-fj46.json +++ b/advisories/github-reviewed/2023/05/GHSA-22gj-8qj2-fj46/GHSA-22gj-8qj2-fj46.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-22gj-8qj2-fj46", - "modified": "2023-05-11T14:01:43Z", + "modified": "2024-04-19T16:22:11Z", "published": "2023-05-02T21:31:48Z", "aliases": [ "CVE-2023-30943" @@ -52,6 +52,18 @@ "type": "PACKAGE", "url": "https://github.com/moodle/moodle" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/54TM5H5PDUDYXOQ7X7PPYWP4AJDAE73I" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MZBWRVUJF7HI53XCJPJ3YJZPOV5HBRUY" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PBFSXRYLT4ICKJVQSRBAOUDMDRVSVBLS" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/54TM5H5PDUDYXOQ7X7PPYWP4AJDAE73I" diff --git a/advisories/github-reviewed/2023/05/GHSA-7mmc-22g7-3xq2/GHSA-7mmc-22g7-3xq2.json b/advisories/github-reviewed/2023/05/GHSA-7mmc-22g7-3xq2/GHSA-7mmc-22g7-3xq2.json index b8bf879d2f6..1688f15597f 100644 --- a/advisories/github-reviewed/2023/05/GHSA-7mmc-22g7-3xq2/GHSA-7mmc-22g7-3xq2.json +++ b/advisories/github-reviewed/2023/05/GHSA-7mmc-22g7-3xq2/GHSA-7mmc-22g7-3xq2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7mmc-22g7-3xq2", - "modified": "2023-05-11T14:02:45Z", + "modified": "2024-04-19T16:22:14Z", "published": "2023-05-02T21:31:48Z", "aliases": [ "CVE-2023-30944" @@ -52,6 +52,18 @@ "type": "PACKAGE", "url": "https://github.com/moodle/moodle" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/54TM5H5PDUDYXOQ7X7PPYWP4AJDAE73I" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MZBWRVUJF7HI53XCJPJ3YJZPOV5HBRUY" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PBFSXRYLT4ICKJVQSRBAOUDMDRVSVBLS" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/54TM5H5PDUDYXOQ7X7PPYWP4AJDAE73I" diff --git a/advisories/github-reviewed/2023/06/GHSA-49mv-vfcp-8gg9/GHSA-49mv-vfcp-8gg9.json b/advisories/github-reviewed/2023/06/GHSA-49mv-vfcp-8gg9/GHSA-49mv-vfcp-8gg9.json index a2355c600cc..becf314a304 100644 --- a/advisories/github-reviewed/2023/06/GHSA-49mv-vfcp-8gg9/GHSA-49mv-vfcp-8gg9.json +++ b/advisories/github-reviewed/2023/06/GHSA-49mv-vfcp-8gg9/GHSA-49mv-vfcp-8gg9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-49mv-vfcp-8gg9", - "modified": "2023-06-30T20:23:28Z", + "modified": "2024-04-19T16:22:19Z", "published": "2023-06-22T21:30:49Z", "aliases": [ "CVE-2023-35132" @@ -119,10 +119,22 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35132" }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2214371" + }, { "type": "PACKAGE", "url": "https://github.com/moodle/moodle" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7A72KX4WU6GK2CX4TKYFGFASPKOEOJFC" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I5QAEAGJ44NVXLAJFJXKARKC45OGEDXT" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7A72KX4WU6GK2CX4TKYFGFASPKOEOJFC" diff --git a/advisories/github-reviewed/2023/06/GHSA-fwfj-8p36-rc64/GHSA-fwfj-8p36-rc64.json b/advisories/github-reviewed/2023/06/GHSA-fwfj-8p36-rc64/GHSA-fwfj-8p36-rc64.json index 0e2cf24252f..be5aa9f9e6a 100644 --- a/advisories/github-reviewed/2023/06/GHSA-fwfj-8p36-rc64/GHSA-fwfj-8p36-rc64.json +++ b/advisories/github-reviewed/2023/06/GHSA-fwfj-8p36-rc64/GHSA-fwfj-8p36-rc64.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fwfj-8p36-rc64", - "modified": "2023-06-30T20:21:14Z", + "modified": "2024-04-19T16:22:16Z", "published": "2023-06-22T21:30:49Z", "aliases": [ "CVE-2023-35131" @@ -100,10 +100,22 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35131" }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2214369" + }, { "type": "PACKAGE", "url": "https://github.com/moodle/moodle" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7A72KX4WU6GK2CX4TKYFGFASPKOEOJFC" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I5QAEAGJ44NVXLAJFJXKARKC45OGEDXT" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7A72KX4WU6GK2CX4TKYFGFASPKOEOJFC" diff --git a/advisories/github-reviewed/2023/06/GHSA-xxp4-mf4h-6cwm/GHSA-xxp4-mf4h-6cwm.json b/advisories/github-reviewed/2023/06/GHSA-xxp4-mf4h-6cwm/GHSA-xxp4-mf4h-6cwm.json index 015851200a1..b5fde12fe90 100644 --- a/advisories/github-reviewed/2023/06/GHSA-xxp4-mf4h-6cwm/GHSA-xxp4-mf4h-6cwm.json +++ b/advisories/github-reviewed/2023/06/GHSA-xxp4-mf4h-6cwm/GHSA-xxp4-mf4h-6cwm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xxp4-mf4h-6cwm", - "modified": "2023-06-30T20:21:55Z", + "modified": "2024-04-19T16:22:21Z", "published": "2023-06-22T21:30:49Z", "aliases": [ "CVE-2023-35133" @@ -119,10 +119,22 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35133" }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2214373" + }, { "type": "PACKAGE", "url": "https://github.com/moodle/moodle" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7A72KX4WU6GK2CX4TKYFGFASPKOEOJFC" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I5QAEAGJ44NVXLAJFJXKARKC45OGEDXT" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7A72KX4WU6GK2CX4TKYFGFASPKOEOJFC" diff --git a/advisories/github-reviewed/2024/04/GHSA-3fp5-2xwh-fxm6/GHSA-3fp5-2xwh-fxm6.json b/advisories/github-reviewed/2024/04/GHSA-3fp5-2xwh-fxm6/GHSA-3fp5-2xwh-fxm6.json index d803ed631fa..281a536d0f6 100644 --- a/advisories/github-reviewed/2024/04/GHSA-3fp5-2xwh-fxm6/GHSA-3fp5-2xwh-fxm6.json +++ b/advisories/github-reviewed/2024/04/GHSA-3fp5-2xwh-fxm6/GHSA-3fp5-2xwh-fxm6.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-3fp5-2xwh-fxm6", - "modified": "2024-04-10T22:04:30Z", + "modified": "2024-04-19T16:20:58Z", "published": "2024-04-10T22:04:30Z", "aliases": [ - + "CVE-2024-32644" ], "summary": "Evmos transaction execution not accounting for all state transition after interaction with precompiles", - "details": "### Context\n\n- [`stateObject`](https://github.com/evmos/evmos/blob/b196a522ba4951890b40992e9f97aa610f8b5f9c/x/evm/statedb/state_object.go#L53-L68): represents the state of an account and is used to store its updates during a state transition. This is accomplished using two in memory Storage variables: `originStorage` and `dirtyStorage`\n- [`StateDB`](https://github.com/evmos/evmos/blob/b196a522ba4951890b40992e9f97aa610f8b5f9c/x/evm/statedb/statedb.go#L33-L55): it is the general interface to retrieve accounts and holds a map of stateObjects.\n\n### Impact\n\nAn external contributor, @iczc, discovered a way to mint arbitrary tokens due to the possibility to have two different states not in sync during the execution of a transaction. The exploit is based on the fact that to sync the Cosmos SDK state and the EVM one, we rely on the `stateDB.Commit()` method. When we call this method, we iterate though all the `dirtyStorage` and, **if and only if** it is different than the `originStorage`, we [set the new state](https://github.com/evmos/evmos/blob/b196a522ba4951890b40992e9f97aa610f8b5f9c/x/evm/statedb/statedb.go#L460-L465). Setting the new state means we update the Cosmos SDK KVStore. \n\nBelow, are described the steps to perform the attack:\n\n- User send a tx to a smart contract (SC) that is calling a precompile. \n- The SC perform a state transition of its state from A to B.\n- The SC call the precompile.\n- The SC perform a state transition of its state from B to A (revert of the previous).\n- Once the transaction is executed, and the final **Commit** is performed, the state A will not be committed to the store because A is the same as `originStorage`. \n\nIf the tx is executed correctly, this is what happens at the store level:\n\n- Initial state A is loaded from the KVStore and the dirtyStorage is set to B.\n- Before running the precompile, the `dirtyStorage` is committed to the KVStore without changing the `originStorage`.\n- Now, since we have a `dirtyStorage`, it is updated to the previous value A without changing the `originStorage`.\n\nSince the tx executed correctly, the evm calls the commit to persist the dirtyStorage. However, since dirtyStorage is equal to originStorage, nothing will be changed.\n\nTo summarize, if a contract storage state that is the same before and after a transaction, but is changed during the transaction and can call an external contract after the change, it can be exploited to make the transaction similar to non-atomic. The vulnerability is **critical** since this could lead to drain of funds through creative SC interactions. \n\n### Patches\n\nThe issue has been patched in versions >=V17.0.0. \n\n## For more information\nIf you have any questions or comments about this advisory:\n\nReach out to the Core Team in [Discord](https://discord.gg/evmos)\nOpen a discussion in [evmos/evmos](https://github.com/evmos/evmos/discussions)\nEmail us at [security@evmos.org](mailto:security@evmos.org) for security questions\nFor Press, email us at [evmos@west-comms.com](mailto:evmos@west-comms.com).\n", + "details": "### Context\n\n- [`stateObject`](https://github.com/evmos/evmos/blob/b196a522ba4951890b40992e9f97aa610f8b5f9c/x/evm/statedb/state_object.go#L53-L68): represents the state of an account and is used to store its updates during a state transition. This is accomplished using two in memory Storage variables: `originStorage` and `dirtyStorage`\n- [`StateDB`](https://github.com/evmos/evmos/blob/b196a522ba4951890b40992e9f97aa610f8b5f9c/x/evm/statedb/statedb.go#L33-L55): it is the general interface to retrieve accounts and holds a map of stateObjects.\n\n### Impact\n\nAn external contributor, @iczc, discovered a way to mint arbitrary tokens due to the possibility to have two different states not in sync during the execution of a transaction. The exploit is based on the fact that to sync the Cosmos SDK state and the EVM one, we rely on the `stateDB.Commit()` method. When we call this method, we iterate though all the `dirtyStorage` and, **if and only if** it is different than the `originStorage`, we [set the new state](https://github.com/evmos/evmos/blob/b196a522ba4951890b40992e9f97aa610f8b5f9c/x/evm/statedb/statedb.go#L460-L465). Setting the new state means we update the Cosmos SDK KVStore. \n\nBelow, are described the steps to perform the attack:\n\n- User send a tx to a smart contract (SC) that is calling a precompile. \n- The SC perform a state transition of its state from A to B.\n- The SC call the precompile.\n- The SC perform a state transition of its state from B to A (revert of the previous).\n- Once the transaction is executed, and the final **Commit** is performed, the state A will not be committed to the store because A is the same as `originStorage`. \n\nIf the tx is executed correctly, this is what happens at the store level:\n\n- Initial state A is loaded from the KVStore and the dirtyStorage is set to B.\n- Before running the precompile, the `dirtyStorage` is committed to the KVStore without changing the `originStorage`.\n- Now, since we have a `dirtyStorage`, it is updated to the previous value A without changing the `originStorage`.\n\nSince the tx executed correctly, the evm calls the commit to persist the dirtyStorage. However, since dirtyStorage is equal to originStorage, nothing will be changed.\n\nTo summarize, if a contract storage state that is the same before and after a transaction, but is changed during the transaction and can call an external contract after the change, it can be exploited to make the transaction similar to non-atomic. The vulnerability is **critical** since this could lead to drain of funds through creative SC interactions. \n\n### Severity\n\nBased on [ImmuneFi Severity Classification System](https://immunefisupport.zendesk.com/hc/en-us/articles/13332717597585-Severity-Classification-System) the severity was evaluated to `Critical` since the attack could have lead to direct loss of funds.\n\n### Patches\n\nThe issue has been patched in versions >=V17.0.0. \n\n## For more information\nIf you have any questions or comments about this advisory:\n\nReach out to the Core Team in [Discord](https://discord.gg/evmos)\nOpen a discussion in [evmos/evmos](https://github.com/evmos/evmos/discussions)\nEmail us at [security@evmos.org](mailto:security@evmos.org) for security questions\n", "severity": [ { "type": "CVSS_V3", @@ -37,158 +37,6 @@ "last_known_affected_version_range": "<= 16.0.4" } }, - { - "package": { - "ecosystem": "Go", - "name": "github.com/evmos/evmos/v15" - }, - "ranges": [ - { - "type": "ECOSYSTEM", - "events": [ - { - "introduced": "0" - }, - { - "last_affected": "15.0.0" - } - ] - } - ] - }, - { - "package": { - "ecosystem": "Go", - "name": "github.com/evmos/evmos/v14" - }, - "ranges": [ - { - "type": "ECOSYSTEM", - "events": [ - { - "introduced": "0" - }, - { - "last_affected": "14.1.0" - } - ] - } - ] - }, - { - "package": { - "ecosystem": "Go", - "name": "github.com/evmos/evmos/v13" - }, - "ranges": [ - { - "type": "ECOSYSTEM", - "events": [ - { - "introduced": "0" - }, - { - "last_affected": "13.0.2" - } - ] - } - ] - }, - { - "package": { - "ecosystem": "Go", - "name": "github.com/evmos/evmos/v12" - }, - "ranges": [ - { - "type": "ECOSYSTEM", - "events": [ - { - "introduced": "0" - }, - { - "last_affected": "12.1.6" - } - ] - } - ] - }, - { - "package": { - "ecosystem": "Go", - "name": "github.com/evmos/evmos/v11" - }, - "ranges": [ - { - "type": "ECOSYSTEM", - "events": [ - { - "introduced": "0" - }, - { - "last_affected": "11.0.2" - } - ] - } - ] - }, - { - "package": { - "ecosystem": "Go", - "name": "github.com/evmos/evmos/v10" - }, - "ranges": [ - { - "type": "ECOSYSTEM", - "events": [ - { - "introduced": "0" - }, - { - "last_affected": "10.0.1" - } - ] - } - ] - }, - { - "package": { - "ecosystem": "Go", - "name": "github.com/evmos/evmos/v9" - }, - "ranges": [ - { - "type": "ECOSYSTEM", - "events": [ - { - "introduced": "0" - }, - { - "last_affected": "9.1.0" - } - ] - } - ] - }, - { - "package": { - "ecosystem": "Go", - "name": "github.com/evmos/evmos/v8" - }, - "ranges": [ - { - "type": "ECOSYSTEM", - "events": [ - { - "introduced": "0" - }, - { - "last_affected": "8.2.3" - } - ] - } - ] - }, { "package": { "ecosystem": "Go", @@ -347,6 +195,14 @@ "type": "WEB", "url": "https://github.com/evmos/evmos/security/advisories/GHSA-3fp5-2xwh-fxm6" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32644" + }, + { + "type": "WEB", + "url": "https://github.com/evmos/evmos/commit/08982b5ee726b97bc50eaf58d1914829648b6a5f" + }, { "type": "PACKAGE", "url": "https://github.com/evmos/evmos" @@ -358,6 +214,10 @@ { "type": "WEB", "url": "https://github.com/evmos/evmos/blob/b196a522ba4951890b40992e9f97aa610f8b5f9c/x/evm/statedb/statedb.go#L33-L55" + }, + { + "type": "WEB", + "url": "https://github.com/evmos/evmos/blob/b196a522ba4951890b40992e9f97aa610f8b5f9c/x/evm/statedb/statedb.go#L460-L465" } ], "database_specific": { @@ -367,6 +227,6 @@ "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2024-04-10T22:04:30Z", - "nvd_published_at": null + "nvd_published_at": "2024-04-19T15:15:50Z" } } \ No newline at end of file