blob: b0ec19c686f14297dcd7e14d044db6b03eeace15 [file] [log] [blame]
id: GO-2025-3476
modules:
- module: github.com/cosmos/cosmos-sdk
versions:
- fixed: 0.47.16-ics-lsm
- introduced: 0.50.0-alpha.0
- fixed: 0.50.12
vulnerable_at: 0.50.11
packages:
- package: github.com/cosmos/cosmos-sdk/x/group
symbols:
- PercentageDecisionPolicy.Allow
- package: github.com/cosmos/cosmos-sdk/x/group/keeper
symbols:
- Keeper.UpdateGroupMembers
- package: github.com/cosmos/cosmos-sdk/x/group/simulation
symbols:
- SimulateMsgUpdateGroupMembers
derived_symbols:
- WeightedOperations
summary: 'Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk'
ghsas:
- GHSA-x5vx-95h7-rv4p
references:
- advisory: https://github.com/cosmos/cosmos-sdk/security/advisories/GHSA-x5vx-95h7-rv4p
- fix: https://github.com/cosmos/cosmos-sdk/commit/0a98b65b24900a0e608866c78f172cf8e4140aea
- web: https://github.com/cosmos/cosmos-sdk/releases/tag/v0.47.16
- web: https://github.com/cosmos/cosmos-sdk/releases/tag/v0.50.12
source:
id: GHSA-x5vx-95h7-rv4p
created: 2025-02-26T12:35:33.327096-05:00
review_status: REVIEWED