CVE-2023-33964
mx-chain-go does not treat invalid transaction with wrong username correctly
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.6EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
31 May 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
mx-chain-go is an implementation of the MultiversX blockchain protocol written in the Go language. Metachain cannot process a cross-shard miniblock. Prior to version 1.4.16, an invalid transaction with the wrong username on metachain is not treated correctly on the metachain transaction processor. This is strictly a processing issue that could have happened on MultiversX chain. If an error like this had occurred, the metachain would have stopped notarizing blocks from the shard chains. The resuming of notarization is possible only after applying a patched binary version. A patch in version 1.4.16 introduces `processIfTxErrorCrossShard` for the metachain transaction processor. There are no known workarounds for this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Affected products
multiversx · mx-chain-goWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →