{"id":"GHSA-8qxh-2gh8-r923","summary":"cheqd-node subject to Cosmos SDK \"Barberry\" vulnerability","details":"### Impact\nThis [vulnerability dubbed \"Barberry\" affects the Cosmos SDK framework](https://forum.cosmos.network/t/cosmos-sdk-security-advisory-barberry/10825) used by `cheqd-node` as base.\n\nIt impacts the way Cosmos SDK handles vesting accounts, and can therefore be a high-impact vulnerability for any network running the framework.\n\nThere is no vulnerability in the DID/resource modules for `cheqd-node`.\n\n### Patches\nNode operators are requested to upgrade to [cheqd-node v1.4.4](https://github.com/cheqd/cheqd-node/releases/tag/v1.4.4). This is not a state-breaking release and does not require a coordinated upgrade across all node operators.\n\nThis vulnerability was patched in [Cosmos SDK v0.46.13](https://github.com/cosmos/cosmos-sdk/releases/tag/v0.46.13). Since this version switches to Go v1.19 and also changes the namespace of many Cosmos protobuf packages, the Barberry fix was [backported to cheqd's fork of Cosmos SDK](https://github.com/cheqd/cosmos-sdk/releases/tag/v0.46.10-barberry).\n\n### Mitigation\nWhen at least ~**33**% of the voting power of the network has deployed the recommended version of the software, any attack would be unsuccessful but cause a chain halt.\n\nOnce at least ~**67**% of the voting power of the network has deployed recommended version of the software, the attack would be unsuccessful _without_ a chain halt.\n\n### Workarounds\nNo. Node operators are recommended to upgrade to the latest release version.\n\n### References\n- [\"Barberry\" vulnerability security advisory](https://forum.cosmos.network/t/cosmos-sdk-security-advisory-barberry/10825)\n- [Cosmos SDK v0.46.13 release notes](https://github.com/cosmos/cosmos-sdk/releases/tag/v0.46.13)\n","modified":"2023-06-12T18:34:26Z","published":"2023-06-12T18:34:26Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2023-06-12T18:34:26Z","nvd_published_at":null,"cwe_ids":[]},"references":[{"type":"WEB","url":"https://github.com/cheqd/cheqd-node/security/advisories/GHSA-8qxh-2gh8-r923"},{"type":"WEB","url":"https://forum.cosmos.network/t/cosmos-sdk-security-advisory-barberry/10825"},{"type":"PACKAGE","url":"https://github.com/cheqd/cheqd-node"},{"type":"WEB","url":"https://github.com/cosmos/cosmos-sdk/releases/tag/v0.46.13"}],"affected":[{"package":{"name":"github.com/cheqd/cheqd-node","ecosystem":"Go","purl":"pkg:golang/github.com/cheqd/cheqd-node"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.4.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-8qxh-2gh8-r923/GHSA-8qxh-2gh8-r923.json"}}],"schema_version":"1.9.0"}