
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability was discovered in go-spacemesh, a Go implementation of the Spacemesh protocol full node. The vulnerability (CVE-2024-34360) allows nodes to publish activation transactions (ATXs) which reference the incorrect previous ATX of the Smesher that created the ATX. The issue was disclosed on May 14, 2024, and affects versions prior to go-spacemesh 1.5.2-hotfix1 and Spacemesh API 1.37.1 (GitHub Advisory).
ATXs are expected to form a single chain from the newest to the first ATX ever published by an identity. The vulnerability breaks this protocol rule by allowing Smeshers to reference an earlier (but not the latest) ATX as previous. The issue has been assigned a CVSS v3.1 base score of 8.2 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N, indicating network attack vector, low attack complexity, and no privileges or user interaction required (GitHub Advisory).
The vulnerability can serve as an attack vector where Nodes are rewarded for holding their PoST (Proof of Space-Time) data for less than one epoch while still being eligible for rewards. This breaks the intended protocol security model and could potentially impact the network's reward distribution system (GitHub Advisory).
The vulnerability is exploitable over the network with low complexity and requires no special privileges or user interaction. The attack can be performed by publishing ATXs that reference incorrect previous ATXs, allowing attackers to potentially claim unearned rewards (GitHub Advisory).
The vulnerability has been patched in go-spacemesh version 1.5.2-hotfix1 and Spacemesh API version 1.37.1. The fixes include preventing the publishing of incorrect ATXs and implementing the creation of malfeasance proofs for identities that published invalid ATXs. No workarounds are available, and users are urged to update to the patched versions (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."