| id: GO-2024-2572 |
| modules: |
| - module: github.com/cosmos/cosmos-sdk |
| versions: |
| - fixed: 0.47.9 |
| - introduced: 0.50.0 |
| - fixed: 0.50.4 |
| vulnerable_at: 0.50.3 |
| packages: |
| - package: github.com/cosmos/cosmos-sdk/x/auth/vesting |
| symbols: |
| - msgServer.CreatePeriodicVestingAccount |
| summary: |- |
| Missing BlockedAddressed Validation in Vesting Module in |
| github.com/cosmos/cosmos-sdk |
| ghsas: |
| - GHSA-4j93-fm92-rp4m |
| references: |
| - advisory: https://github.com/cosmos/cosmos-sdk/security/advisories/GHSA-4j93-fm92-rp4m |
| - fix: https://github.com/cosmos/cosmos-sdk/commit/c05850241e2d615721e3492d15fee4e1deec082b |
| - web: https://github.com/cosmos/cosmos-sdk/releases/tag/v0.47.9 |
| - web: https://github.com/cosmos/cosmos-sdk/releases/tag/v0.50.4 |
| source: |
| id: GHSA-4j93-fm92-rp4m |
| created: 2024-07-01T15:01:58.512805-04:00 |
| review_status: REVIEWED |