#39364 [BC-Critical] Trusting heavily on "appData" enables infinite SHM duplication through double-spend exploit
Description
Brief/Intro
Vulnerability Details
if (ShardeumFlags.autoGenerateAccessList && appData.accessList) {
shardusMemoryPatterns = appData.shardusMemoryPatterns // should not trust it
...
}Impact Details
Link to Proof of Concept
Proof of Concept
Proof of Concept
Previous#39850 [BC-Medium] Bypass TransferFromSecureAccount transaction validationsNext#39882 [BC-Insight] data unsubscribe same node replay
Was this helpful?