CVE-2023-34451

CVSS 3.1 Score 8.2 of 10 (high)

Details

Published Jul 3, 2023
Updated: Jul 17, 2023
CWE ID 401

Summary

CVE-2023-34451 is a vulnerability affecting CometBFT, a Byzantine Fault Tolerant middleware. In versions v0.37.0, v0.37.1, v0.34.28, and earlier, the mempool's list and map data structures can become unsynchronized. This issue results in multiple copies of the same transaction being present in the list, while the map only tracks the index of a single copy. Once transactions are duplicated, they cannot be removed without restarting the node. An attacker can exploit this vulnerability by introducing out-of-sync transactions, potentially leading to a significant number of transactions being stuck in the mempool, aiming to bring down the target node. The vulnerability is fixed in releases v0.34.29 and v0.37.2, and implementing a larger cache size or hiding transaction submission RPCs can provide some mitigation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2023-34451 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions