PT-2023-28592 · Cardano · Hydra

·

CVE-2023-42806

·

Published

2023-09-21

·

Updated

2023-10-03

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hydra versions prior to 0.13.0
Description Hydra is the layer-two scalability solution for Cardano. Not signing and verifying cid allows an attacker, who must be a participant of this head, to use a snapshot from an old head instance with the same participants to close the head or contest the state with it. This can lead to an incorrect distribution of value, resulting in a value extraction attack, or prevent the head from finalizing due to inconsistent value availability, causing a denial of service.
Recommendations For versions prior to 0.13.0, as a temporary workaround, consider rotating keys between heads to avoid reusing keys and resulting in the same multi-signature participants. A patch is planned for version 0.13.0.

Exploit

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-42806
GHSA-GR36-MC6V-72QQ

Affected Products

Hydra