漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
hydra-node dangerously assumes L1 event finality and does not consider failed transactions
Vulnerability Description
Hydra is a layer-two scalability solution for Cardano. Prior to version 0.22.0, the process assumes L1 event finality and does not consider failed transactions. Currently, Cardano L1 is monitored for certain events which are necessary for state progression. At the moment, Hydra considers those events as finalized as soon as they are recognized by the node participants making such transactions the target of re-org attacks. The system does not currently consider the fact that failed transactions on the Cardano L1 can indeed appear in blocks because these transactions are so infrequent. This issue has been patched in version 0.22.0.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
Vulnerability Type
对异常条件的处理不恰当
Vulnerability Title
Hydra 安全漏洞
Vulnerability Description
Hydra是Nix开源的一个基于Nix项目的持续集成服务。 Hydra 0.22.0之前版本存在安全漏洞,该漏洞源于未考虑Cardano L1上的失败交易,可能导致重组织攻击。
CVSS Information
N/A
Vulnerability Type
N/A