{"id":"GHSA-j92c-mmf7-j5x5","aliases":["GO-2022-1066"],"url":"https://o3.security/vulnerability/GHSA-j92c-mmf7-j5x5","summary":"Potential inter-blockchain communication (IBC) protocol compromise via \"Dragonberry\" vulnerability in cheqd","details":"### Impact\nThis vulnerability affects IBC transfers due to a security vulnerability dubbed \"Dragonberry\" upstream in [Cosmos SDK](https://github.com/cosmos/cosmos-sdk/releases/tag/v0.45.9). The vulnerability could allow malicious attackers to compromise chain-to-chain IBC transfers.\n\nThere is no vulnerability in the DID/resource modules for cheqd-node.\n\n### Patches\nNode operators are requested to upgrade to [cheqd-node v0.6.9](https://github.com/cheqd/cheqd-node/releases/tag/0.6.9) as soon as possible. Installation instructions are in the release notes. Please do not install any beta/pre-release versions.\n\n### Workarounds\nNo. The patch takes effect when more than 2/3rds of the voting power of the cheqd network has upgraded to this patch.\n\nAn emergency hotfix was released previously under v0.6.8 but this is now deprecated since [Cosmos SDK v0.45.9](https://github.com/cosmos/cosmos-sdk/releases/tag/v0.45.9) officially fixes this upstream.\n\n### References\n- [IBC Security Advisory on \"Dragonberry\"](https://forum.cosmos.network/t/ibc-security-advisory-dragonberry/7702/1) (and [associated security vulnerability \"Dragonfruit\"](https://forum.cosmos.network/t/cosmos-sdk-security-advisory-dragonfruit/7614))\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [cheqd-node repo](https://github.com/cheqd/cheqd-node/issues)\n* Email us at [security-github@cheqd.io](mailto:security-github@cheqd.io)\n* Message us on our community [Slack](http://cheqd.link/join-cheqd-slack) or [Discord](http://cheqd.link/discord-github)","published":"2022-10-18T17:27:36Z","modified":"2024-08-21T16:28:58.799996Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/cheqd/cheqd-node","fixedVersion":"0.6.9"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/cheqd/cheqd-node/security/advisories/GHSA-j92c-mmf7-j5x5"},{"type":"WEB","url":"https://forum.cosmos.network/t/ibc-security-advisory-dragonberry/7702/1"},{"type":"PACKAGE","url":"https://github.com/cheqd/cheqd-node"},{"type":"WEB","url":"https://github.com/cosmos/cosmos-sdk/releases/tag/v0.45.9"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-08-21T16:28:58.799996Z"}}