CVE-2023-42448

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Oct 4, 2023
Updated: Oct 10, 2023
CWE ID 1284
CWE ID 20

Summary

CVE-2023-42448 is a vulnerability affecting the Hydra scalability solution for Cardano, specifically versions prior to 0.13.0. The issue lies in the `checkClose` function of the head validator, which fails to enforce the specification requiring the contestation period in the UTxO datum to remain unchanged during the transition from Open to Closed. This vulnerability could be exploited by a malicious participant to either bypass contestation and fanout the head, or prevent others from redistributing funds locked in the head. The vulnerability has been addressed in version 0.13.0 with the implementation of a patch.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share