{"id":"GHSA-8qxh-2gh8-r923","aliases":[],"url":"https://o3.security/vulnerability/GHSA-8qxh-2gh8-r923","summary":"cheqd-node subject to Cosmos SDK \"Barberry\" vulnerability","details":"### Impact\nThis [vulnerability dubbed \"Barberry\" affects the Cosmos SDK framework](https://forum.cosmos.network/t/cosmos-sdk-security-advisory-barberry/10825) used by `cheqd-node` as base.\n\nIt impacts the way Cosmos SDK handles vesting accounts, and can therefore be a high-impact vulnerability for any network running the framework.\n\nThere is no vulnerability in the DID/resource modules for `cheqd-node`.\n\n### Patches\nNode operators are requested to upgrade to [cheqd-node v1.4.4](https://github.com/cheqd/cheqd-node/releases/tag/v1.4.4). This is not a state-breaking release and does not require a coordinated upgrade across all node operators.\n\nThis vulnerability was patched in [Cosmos SDK v0.46.13](https://github.com/cosmos/cosmos-sdk/releases/tag/v0.46.13). Since this version switches to Go v1.19 and also changes the namespace of many Cosmos protobuf packages, the Barberry fix was [backported to cheqd's fork of Cosmos SDK](https://github.com/cheqd/cosmos-sdk/releases/tag/v0.46.10-barberry).\n\n### Mitigation\nWhen at least ~**33**% of the voting power of the network has deployed the recommended version of the software, any attack would be unsuccessful but cause a chain halt.\n\nOnce at least ~**67**% of the voting power of the network has deployed recommended version of the software, the attack would be unsuccessful _without_ a chain halt.\n\n### Workarounds\nNo. Node operators are recommended to upgrade to the latest release version.\n\n### References\n- [\"Barberry\" vulnerability security advisory](https://forum.cosmos.network/t/cosmos-sdk-security-advisory-barberry/10825)\n- [Cosmos SDK v0.46.13 release notes](https://github.com/cosmos/cosmos-sdk/releases/tag/v0.46.13)\n","published":"2023-06-12T18:34:26Z","modified":"2023-06-12T18:34:26Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/cheqd/cheqd-node","fixedVersion":"1.4.4"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/cheqd/cheqd-node/security/advisories/GHSA-8qxh-2gh8-r923"},{"type":"WEB","url":"https://forum.cosmos.network/t/cosmos-sdk-security-advisory-barberry/10825"},{"type":"PACKAGE","url":"https://github.com/cheqd/cheqd-node"},{"type":"WEB","url":"https://github.com/cosmos/cosmos-sdk/releases/tag/v0.46.13"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-06-12T18:34:26Z"}}