CVE-2021-41135
Last modified
CVE-2021-41135 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. The Cosmos-SDK is a framework for building blockchain applications in Golang. Affected versions of the SDK were vulnerable to a consensus halt due to non-deterministic behaviour in a ValidateBasic method in the x/authz module. EPSS estimates a 1.66% chance of exploitation in the next 30 days.
Description
The Cosmos-SDK is a framework for building blockchain applications in Golang. Affected versions of the SDK were vulnerable to a consensus halt due to non-deterministic behaviour in a ValidateBasic method in the x/authz module. The MsgGrant of the x/authz module contains a Grant field which includes a user-defined expiration time for when the authorization grant expires. In Grant.ValidateBasic(), that time is compared to the node’s local clock time. Any chain running an affected version of the SDK with the authz module enabled could be halted by anyone with the ability to send transactions on that chain. Recovery would require applying the patch and rolling back the latest block. Users are advised to update to version 0.44.2.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Interchain | Cosmos Sdk | >= 0.43.0, < 0.44.2 |
References
- https://github.com/cosmos/cosmos-sdk/commit/68ab790a761e80d3674f821794cf18ccbfed45eePatch, Third Party Advisory
- https://github.com/cosmos/cosmos-sdk/security/advisories/GHSA-2p6r-37p9-89p2Third Party Advisory
- https://github.com/cosmos/cosmos-sdk/commit/68ab790a761e80d3674f821794cf18ccbfed45eePatch, Third Party Advisory
- https://github.com/cosmos/cosmos-sdk/security/advisories/GHSA-2p6r-37p9-89p2Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-41135?
How severe is CVE-2021-41135?
How do I fix CVE-2021-41135?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-4113Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2021-41130Extensible Service Proxy, a.k.a. ESP is a proxy which enable…5.4
- CVE-2021-41131python-tuf is a Python reference implementation of The Updat…8.7
- CVE-2021-41132OMERO.web provides a web based client and plugin infrastruct…6.1
- CVE-2021-41133Flatpak is a system for building, distributing, and running …7.8
- CVE-2021-41134nbdime provides tools for diffing and merging of Jupyter Not…5.4
- CVE-2021-41136Puma is a HTTP 1.1 server for Ruby/Rack applications. Prior …3.7
- CVE-2021-41137Minio is a Kubernetes native application for cloud storage. …8.8
- CVE-2021-41138Frontier is Substrate's Ethereum compatibility layer. In the…5.3
- CVE-2021-41139Anuko Time Tracker is an open source, web-based time trackin…6.1
- CVE-2021-4114Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2021-41140Discourse-reactions is a plugin for the Discourse platform t…5.3
Are you affected by CVE-2021-41135?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
