Vulnerability DatabaseGHSA-fpgj-cr28-fvpx

GHSA-fpgj-cr28-fvpx
vulnerability analysis and mitigation

Overview

A medium severity vulnerability (GHSA-fpgj-cr28-fvpx) was identified in wasmd version 0.52.0, affecting the smart contract query functionality. The vulnerability was discovered on July 25, 2024, through the Cosmos Bug Bounty Program and has been patched in wasmd version 0.53.0 (CosmWasm Advisory).

Technical details

The vulnerability relates to a non-deterministic modulequerysafe query in the wasmd implementation. The issue was addressed by removing the cosmos.query.v1.modulequerysafe annotation from the SmartContractState RPC in the protocol buffer definition (Wasmd Commit).

Impact

The vulnerability was classified as Medium severity according to Amulet's Severity Classification Framework ACMv1, with Moderate impact and Likely likelihood (CosmWasm Advisory).

Mitigation and workarounds

Users are advised to upgrade to wasmd version 0.53.0 which contains the patch. The upgrade process involves updating the github.com/CosmWasm/wasmd dependency in go.mod to version 0.53.0, running go mod tidy, and following regular chain upgrade practices (CosmWasm Advisory).

Community reactions

The patch release was officially announced on X (formerly Twitter) on August 20, 2024 (CosmWasm Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management