CVE-2020-15091
Last modified
CVE-2020-15091 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. TenderMint from version 0.33.0 and before version 0.33.6 allows block proposers to include signatures for the wrong block. This may happen naturally if you start a network, have it run for some time and restart it (**without changing chainID**). EPSS estimates a 0.91% chance of exploitation in the next 30 days.
Description
TenderMint from version 0.33.0 and before version 0.33.6 allows block proposers to include signatures for the wrong block. This may happen naturally if you start a network, have it run for some time and restart it (**without changing chainID**). A malicious block proposer (even with a minimal amount of stake) can use this vulnerability to completely halt the network. This issue is fixed in Tendermint 0.33.6 which checks all the signatures are for the block with 2/3+ majority before creating a commit.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tendermint | Tendermint | >= 0.33.0, < 0.33.6 |
References
- https://github.com/tendermint/tendermint/commit/480b995a31727593f58b361af979054d17d84340Patch, Third Party Advisory
- https://github.com/tendermint/tendermint/issues/4926Exploit, Issue Tracking, Third Party Advisory
- https://github.com/tendermint/tendermint/security/advisories/GHSA-6jqj-f58p-mrw3Exploit, Third Party Advisory
- https://github.com/tendermint/tendermint/commit/480b995a31727593f58b361af979054d17d84340Patch, Third Party Advisory
- https://github.com/tendermint/tendermint/issues/4926Exploit, Issue Tracking, Third Party Advisory
- https://github.com/tendermint/tendermint/security/advisories/GHSA-6jqj-f58p-mrw3Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-15091?
How severe is CVE-2020-15091?
How do I fix CVE-2020-15091?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-15083In PrestaShop from version 1.7.0.0 and before version 1.7.6.…6.1
- CVE-2020-15084In express-jwt (NPM package) up and including version 5.3.3,…9.1
- CVE-2020-15085In Saleor Storefront before version 2.10.3, request data use…6.1
- CVE-2020-15086In TYPO3 installations with the "mediace" extension from ver…9.8
- CVE-2020-15087In Presto before version 337, authenticated users can bypass…8.8
- CVE-2020-1509An elevation of privilege vulnerability exists in the Local …7.8
- CVE-2020-15092In TimelineJS before version 3.7.0, some user data renders a…4.8
- CVE-2020-15093The tough library (Rust/crates.io) prior to version 0.7.1 do…8.6
- CVE-2020-15094In Symfony before versions 4.4.13 and 5.1.5, the CachingHttp…8.8
- CVE-2020-15095Versions of the npm CLI prior to 6.14.6 are vulnerable to an…4.4
- CVE-2020-15096In Electron before versions 6.1.1, 7.2.4, 8.2.4, and 9.0.0-b…6.8
- CVE-2020-15097loklak is an open-source server application which is able to…9.1
Are you affected by CVE-2020-15091?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
