CVE-2023-42448

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Oct 4, 2023
Updated: Oct 10, 2023
CWE ID 1284
CWE ID 20

Summary

CVE-2023-42448 is a vulnerability affecting the Hydra scalability solution for Cardano, specifically versions prior to 0.13.0. The issue lies in the `checkClose` function of the head validator, which fails to enforce the specification requiring the contestation period in the UTxO datum to remain unchanged during the transition from Open to Closed. This vulnerability could be exploited by a malicious participant to either bypass contestation and fanout the head, or prevent others from redistributing funds locked in the head. The vulnerability has been addressed in version 0.13.0 with the implementation of a patch.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2023-42448 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions