Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/cheqd/cheqd-node
  4. ›
  5. GMS-2023-1809

GMS-2023-1809: cheqd-node affected by Inter-blockchain Communication (IBC) protocol "Huckleberry" vulnerability

June 5, 2023

Impact

This vulnerability affects the ibc-go package for those running full nodes, dubbed “Huckleberry”. According to their advisory:

This issue is low-severity in general, and it has a low impact and likelihood of exploitation. Depending on how a full node is architected, this issue could potentially yield a high or critical severity vulnerability.

There is no vulnerability in the DID/resource modules for cheqd-node.

Patches

Node operators are requested to upgrade to cheqd-node v1.4.2. This is a non-state breaking release, and does not require a coordinated upgrade across all node operators.

Workarounds

No. Node operators are recommended to upgrade to the latest release version.

References

  • “Huckleberry” IBC security advisory
  • ibc-go v6.1.1 release notes

References

  • forum.cosmos.network/t/ibc-security-advisory-huckleberry/10731
  • github.com/advisories/GHSA-7c94-gvvj-r3mg
  • github.com/cheqd/cheqd-node/commit/f325f5f250e150e3e76a5a557669f67b606e34e1
  • github.com/cheqd/cheqd-node/releases/tag/v1.4.2
  • github.com/cheqd/cheqd-node/security/advisories/GHSA-7c94-gvvj-r3mg
  • github.com/cosmos/ibc-go/releases/tag/v6.1.1

Code Behaviors & Features

Detect and mitigate GMS-2023-1809 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.4.2

Fixed versions

  • v1.4.2

Solution

Upgrade to version 1.4.2 or above.

Source file

go/github.com/cheqd/cheqd-node/GMS-2023-1809.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:42 +0000.