CVE-2022-23507 is a medium-severity vulnerability (CVSS 6.5) in Tendermint versions prior to 0.28.0, specifically affecting light client verification in packages like tendermint-light-client. The flaw, an Improper Verification of Cryptographic Signature (CWE-347), allows a light client to be fooled by a header from an untrusted chain if it meets other verification conditions, due to a failure to check matching chain IDs. While the attack vector is currently theoretical with no known proof-of-concept or active exploitation, it could lead to data integrity and confidentiality issues. There are no workarounds, and the issue is patched in Tendermint version 0.28.0.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.28.0CPE matchmatch criteria | cpe:2.3:a:tendermint-light-client-js_project:tendermint-light-client-js:*:*:*:*:rust:*:*:* | ||
< 0.28.0CPE matchmatch criteria | cpe:2.3:a:tendermint-light-client-verifier_project:tendermint-light-client-verifier:*:*:*:*:*:rust:*:* | ||
< 0.28.0CPE matchmatch criteria | cpe:2.3:a:tendermint-light-client_project:tendermint-light-client:*:*:*:*:rust:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.