CVE-2023-42449

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Oct 4, 2023
Updated: Oct 10, 2023
CWE ID 20

Summary

CVE-2023-42449 is a vulnerability that affects the Hydra two-layer scalability solution for Cardano. Specifically, versions prior to 0.13.0 are susceptible to this issue. The vulnerability allows a malicious head initializer to extract one or more PTs (Plutus Tokens) during the initialization process, due to incorrect data validation logic in the head token minting policy. This flaw can be exploited by removing a PT from the Hydra scripts, preventing other participants from reclaiming their funds committed into the head. The potential danger posed by this vulnerability is significant, as it can lead to financial losses for participants unable to retrieve their funds. To remediate this issue, organizations using Hydra should update to version 0.13.0 or later, which includes fixes for this vulnerability and enhances data validation processes.

Share

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2023-42449 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options