| id: GO-2024-3339 |
| modules: |
| - module: cosmossdk.io/x/tx |
| versions: |
| - fixed: 0.13.7 |
| vulnerable_at: 0.13.6 |
| packages: |
| - package: cosmossdk.io/x/tx/decode |
| symbols: |
| - RejectUnknownFields |
| derived_symbols: |
| - Decoder.Decode |
| - RejectUnknownFieldsStrict |
| - module: github.com/cosmos/cosmos-sdk |
| versions: |
| - fixed: 0.47.15 |
| - introduced: 0.50.0-alpha.0 |
| - fixed: 0.50.11 |
| vulnerable_at: 0.50.10 |
| packages: |
| - package: github.com/cosmos/cosmos-sdk/codec/types |
| symbols: |
| - interfaceRegistry.UnpackAny |
| - package: github.com/cosmos/cosmos-sdk/codec/unknownproto |
| symbols: |
| - RejectUnknownFields |
| derived_symbols: |
| - RejectUnknownFieldsStrict |
| summary: |- |
| Transaction decoding may result in a stack overflow or resource exhaustion in |
| github.com/cosmos/cosmos-sdk |
| ghsas: |
| - GHSA-8wcc-m6j2-qxvm |
| references: |
| - advisory: https://github.com/cosmos/cosmos-sdk/security/advisories/GHSA-8wcc-m6j2-qxvm |
| - fix: https://github.com/cosmos/cosmos-sdk/commit/c6b1bdcd5628e3e425a3f02881d3c7db1d7af653 |
| - web: https://github.com/cosmos/cosmos-sdk/releases/tag/v0.47.15 |
| - web: https://github.com/cosmos/cosmos-sdk/releases/tag/v0.50.11 |
| source: |
| id: GHSA-8wcc-m6j2-qxvm |
| created: 2024-12-20T10:42:55.054352-10:00 |
| review_status: REVIEWED |