CVE-2023-42448
CVSS 3.1 Score 8.1 of 10 (high)
Details
Summary
CVE-2023-42448 is a vulnerability affecting the Hydra scalability solution for Cardano, specifically versions prior to 0.13.0. The issue lies in the `checkClose` function of the head validator, which fails to enforce the specification requiring the contestation period in the UTxO datum to remain unchanged during the transition from Open to Closed. This vulnerability could be exploited by a malicious participant to either bypass contestation and fanout the head, or prevent others from redistributing funds locked in the head. The vulnerability has been addressed in version 0.13.0 with the implementation of a patch.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Input Output (IOHK)