Vulnerability Report: GO-2021-0090
- CVE-2020-15091, GHSA-6jqj-f58p-mrw3
- Affects: github.com/tendermint/tendermint
- Published: Apr 14, 2021
- Modified: Jun 12, 2023
Proposed commits may contain signatures for blocks not contained within the commit. Instead of skipping these signatures, they cause failure during verification. A malicious proposer can use this to force consensus failures.
from v0.33.0 before v0.34.0-dev1.0.20200702134149-480b995a3172
- Neeraj Murarka
See anything missing or incorrect? Suggest an edit to this report.