{"id":"GO-2023-1821","summary":"The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk","details":"If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended.\n\nNo patch will be released, as the package is planned to be deprecated and replaced.","aliases":["GHSA-qfc5-6r3j-jj22"],"modified":"2024-05-20T16:03:47Z","published":"2023-07-05T17:29:41Z","database_specific":{"url":"https://pkg.go.dev/vuln/GO-2023-1821","review_status":"REVIEWED"},"references":[{"type":"ADVISORY","url":"https://github.com/cosmos/cosmos-sdk/security/advisories/GHSA-qfc5-6r3j-jj22"},{"type":"REPORT","url":"https://github.com/cosmos/cosmos-sdk/issues/15325"},{"type":"REPORT","url":"https://github.com/cosmos/cosmos-sdk/issues/15706"}],"affected":[{"package":{"name":"github.com/cosmos/cosmos-sdk","ecosystem":"Go","purl":"pkg:golang/github.com/cosmos/cosmos-sdk"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/cosmos/cosmos-sdk/x/crisis"}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2023-1821.json"}}],"schema_version":"1.7.3"}