{"id":"GHSA-j92c-mmf7-j5x5","summary":"Potential inter-blockchain communication (IBC) protocol compromise via \"Dragonberry\" vulnerability in cheqd","details":"### Impact\nThis vulnerability affects IBC transfers due to a security vulnerability dubbed \"Dragonberry\" upstream in [Cosmos SDK](https://github.com/cosmos/cosmos-sdk/releases/tag/v0.45.9). The vulnerability could allow malicious attackers to compromise chain-to-chain IBC transfers.\n\nThere is no vulnerability in the DID/resource modules for cheqd-node.\n\n### Patches\nNode operators are requested to upgrade to [cheqd-node v0.6.9](https://github.com/cheqd/cheqd-node/releases/tag/0.6.9) as soon as possible. Installation instructions are in the release notes. Please do not install any beta/pre-release versions.\n\n### Workarounds\nNo. The patch takes effect when more than 2/3rds of the voting power of the cheqd network has upgraded to this patch.\n\nAn emergency hotfix was released previously under v0.6.8 but this is now deprecated since [Cosmos SDK v0.45.9](https://github.com/cosmos/cosmos-sdk/releases/tag/v0.45.9) officially fixes this upstream.\n\n### References\n- [IBC Security Advisory on \"Dragonberry\"](https://forum.cosmos.network/t/ibc-security-advisory-dragonberry/7702/1) (and [associated security vulnerability \"Dragonfruit\"](https://forum.cosmos.network/t/cosmos-sdk-security-advisory-dragonfruit/7614))\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [cheqd-node repo](https://github.com/cheqd/cheqd-node/issues)\n* Email us at [security-github@cheqd.io](mailto:security-github@cheqd.io)\n* Message us on our community [Slack](http://cheqd.link/join-cheqd-slack) or [Discord](http://cheqd.link/discord-github)","aliases":["GO-2022-1066"],"modified":"2024-08-21T16:28:58.799996Z","published":"2022-10-18T17:27:36Z","database_specific":{"cwe_ids":[],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-10-18T17:27:36Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/cheqd/cheqd-node/security/advisories/GHSA-j92c-mmf7-j5x5"},{"type":"WEB","url":"https://forum.cosmos.network/t/ibc-security-advisory-dragonberry/7702/1"},{"type":"PACKAGE","url":"https://github.com/cheqd/cheqd-node"},{"type":"WEB","url":"https://github.com/cosmos/cosmos-sdk/releases/tag/v0.45.9"}],"affected":[{"package":{"name":"github.com/cheqd/cheqd-node","ecosystem":"Go","purl":"pkg:golang/github.com/cheqd/cheqd-node"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.6.9"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/10/GHSA-j92c-mmf7-j5x5/GHSA-j92c-mmf7-j5x5.json"}}],"schema_version":"1.9.0"}