CVE-2024-34360
vulnerability analysis and mitigation

Overview

A vulnerability was discovered in go-spacemesh, a Go implementation of the Spacemesh protocol full node. The vulnerability (CVE-2024-34360) allows nodes to publish activation transactions (ATXs) which reference the incorrect previous ATX of the Smesher that created the ATX. The issue was disclosed on May 14, 2024, and affects versions prior to go-spacemesh 1.5.2-hotfix1 and Spacemesh API 1.37.1 (GitHub Advisory).

Technical details

ATXs are expected to form a single chain from the newest to the first ATX ever published by an identity. The vulnerability breaks this protocol rule by allowing Smeshers to reference an earlier (but not the latest) ATX as previous. The issue has been assigned a CVSS v3.1 base score of 8.2 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N, indicating network attack vector, low attack complexity, and no privileges or user interaction required (GitHub Advisory).

Impact

The vulnerability can serve as an attack vector where Nodes are rewarded for holding their PoST (Proof of Space-Time) data for less than one epoch while still being eligible for rewards. This breaks the intended protocol security model and could potentially impact the network's reward distribution system (GitHub Advisory).

Exploitability

The vulnerability is exploitable over the network with low complexity and requires no special privileges or user interaction. The attack can be performed by publishing ATXs that reference incorrect previous ATXs, allowing attackers to potentially claim unearned rewards (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in go-spacemesh version 1.5.2-hotfix1 and Spacemesh API version 1.37.1. The fixes include preventing the publishing of incorrect ATXs and implementing the creation of malfeasance proofs for identities that published invalid ATXs. No workarounds are available, and users are urged to update to the patched versions (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management