39626 [W&A-Critical] malicious validator can overwrite any cycle data
#39626 [W&A-Critical] Malicious Validator Can Overwrite Any Cycle Data
Description
Shardeum Ancillaries Bug Report
Malicious Validator Can Overwrite Any Cycle Data
Summary
Root Cause Analysis
Vulnerability Breakdown
Exploitation Steps
Scenario
Steps to Exploit
Impact
Proposed Fix
Why This Works
Proof of Concept
Proof of Concept (PoC)
Creating a Malicious Validator
Executing the PoC
1. Setup
2. Attack Execution
Previous#39623 [W&A-Low] Blocking the victim's account address from sending transactions via JSON-RPCNext#39820 [W&A-Medium] Blocking all users from interacting with particular contracts/protocols via JSON
Last updated
Was this helpful?