Hyperledger Iroha versions v1.0_beta and v1.0.0_beta-1 are vulnerable to transaction and block signature verification bypass in the transaction and block validator allowing a single node to sign a transaction and/or block multiple times, each with a random nonce, and have other validating nodes accept them as separate valid signatures.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2018-06-01T19:00:00Z

Updated: 2024-09-17T03:34:16.191Z

Reserved: 2017-12-28T00:00:00

Link: CVE-2018-3756

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-06-01T19:29:00.363

Modified: 2018-07-18T15:26:20.317

Link: CVE-2018-3756

cve-icon Redhat

No data.