PT-2023-24605 · Multiversx · Mx-Chain-Go
Iulianpascalau
·
Published
2023-05-31
·
Updated
2024-08-20
·
CVE-2023-33964
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
mx-chain-go versions prior to 1.4.16
Description
The metachain cannot process a cross-shard miniblock. An invalid transaction with the wrong username on metachain is not treated correctly on the metachain transaction processor, which is a processing issue that could have occurred on the MultiversX chain. If such an error occurred, the metachain would have stopped notarizing blocks from the shard chains. The resuming of notarization is possible only after applying a patched binary version. A patch introduces
processIfTxErrorCrossShard for the metachain transaction processor.Recommendations
For versions prior to 1.4.16, update to version 1.4.16 or later, which includes the patch introducing
processIfTxErrorCrossShard for the metachain transaction processor. As a temporary workaround, consider disabling the metachain transaction processor until a patched binary version is applied.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mx-Chain-Go