CVE-2022-46173

Published: Dic 28, 2022 Last Modified: Nov 21, 2024 EU-VD ID: EUVD-2022-7694 Aliases: GHSA-p228-4mrh-ww7r
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,2
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: changed
Confidentiality: none
Integrity: low
Availability: low

Description

AI Translation Available

Elrond-GO is a go implementation for the Elrond Network protocol. Versions prior to 1.3.50 are subject to a processing issue where nodes are affected when trying to process a cross-shard relayed transaction with a smart contract deploy transaction data. The problem was a bad correlation between the transaction caches and the processing component. If the above-mentioned transaction was sent with more gas than required, the smart contract result (SCR transaction) that should have returned the leftover gas, would have been wrongly added to a cache that the processing unit did not consider. The node stopped notarizing metachain blocks. The fix was actually to extend the SCR transaction search in all other caches if it wasn't found in the correct (expected) sharded-cache. There are no known workarounds at this time. This issue has been patched in version 1.3.50.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0035
Percentile
0,6th
Updated

EPSS Score Trend (Last 90 Days)

669

Incorrect Resource Transfer Between Spheres

Draft
Common Consequences
Security Scopes Affected:
Confidentiality Integrity
Potential Impacts:
Read Application Data Modify Application Data Unexpected State
Applicable Platforms
All platforms may be affected
View CWE Details
Application

Elrond Go by Elrond

Version Range Affected
To 1.3.50 (exclusive)
cpe:2.3:a:elrond:elrond_go:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://github.com/ElrondNetwork/elrond-go/commit/39d7ddcb08bb34217dab6daef7cd9…
https://github.com/ElrondNetwork/elrond-go/pull/4718
https://github.com/ElrondNetwork/elrond-go/security/advisories/GHSA-p228-4mrh-w…
https://github.com/ElrondNetwork/elrond-go/commit/39d7ddcb08bb34217dab6daef7cd9…
https://github.com/ElrondNetwork/elrond-go/pull/4718
https://github.com/ElrondNetwork/elrond-go/security/advisories/GHSA-p228-4mrh-w…