Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add reference to ACMv1 in recent advisories #47

Merged
merged 1 commit into from
Aug 22, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion CWAs/CWA-2024-001.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

**Severity**

Low
Low[^1]

**Affected versions:** serde-json-wasm < 1.0.1, < 0.5.2
**Patched versions:** serde-json-wasm 1.0.1, 0.5.2
Expand Down Expand Up @@ -38,3 +38,5 @@ program by reporting a bug, please see <https://hackerone.com/cosmos>.
- 2024-01-24: [Submitted to](https://github.com/rustsec/advisory-db/pull/1867) RustSec Advisory Database
- 2024-02-01: Advisory published
- 2024-02-09: RustSec Advisory Database entry created ([RUSTSEC-2024-0012](https://rustsec.org/advisories/RUSTSEC-2024-0012.html))

[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md
4 changes: 3 additions & 1 deletion CWAs/CWA-2024-002.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

**Severity**

Medium
Medium[^1]

**Affected versions:**

Expand Down Expand Up @@ -47,3 +47,5 @@ Affected if `overflow-checks = true` is not set:
- 2024-04-22: The upcoming patch is announced through the CosmWasm advisories notification list and publicly on X (https://twitter.com/CosmWasm/status/1782439624608030771).
- 2024-04-24: The patch is released.
- 2024-04-24: RustSec Advisory Database entry created ([RUSTSEC-2024-0338](https://rustsec.org/advisories/RUSTSEC-2024-0338.html))

[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md
4 changes: 3 additions & 1 deletion CWAs/CWA-2024-003.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

**Severity**

Low (Moderate + Unlikely)
Low (Moderate + Unlikely)[^1]

**Affected versions:**

Expand Down Expand Up @@ -75,3 +75,5 @@ program by reporting a bug, please see <https://hackerone.com/cosmos>.
- 2024-04-21: Bug reported via Cosmos HackerOne
- 2024-04-25: A patch was created internally
- 2024-07-11: The patch is published and released with wasmd 0.52

[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md
4 changes: 3 additions & 1 deletion CWAs/CWA-2024-004.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

**Severity**

Medium (Moderate + Likely)
Medium (Moderate + Likely)[^1]

**Affected versions:**

Expand Down Expand Up @@ -63,3 +63,5 @@ program by reporting a bug, please see <https://hackerone.com/cosmos>.
- 2024-08-02: Confio developed the patch internally.
- 2024-08-08: Patch released
- 2024-08-08: Updated patched versions to ones that will invalidate the cache

[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md
4 changes: 3 additions & 1 deletion CWAs/CWA-2024-005.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

**Severity**

High (Critical + Likely)
High (Critical + Likely)[^1]

**Affected versions:**

Expand Down Expand Up @@ -46,3 +46,5 @@ program by reporting a bug, please see <https://hackerone.com/cosmos>.
- 2024-08-19: Patch release announced though notifications list.
- 2024-08-20: Patch release announced on X: <https://x.com/CosmWasm/status/1825814580217381334>.
- 2024-08-21: Patch released.

[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md
4 changes: 3 additions & 1 deletion CWAs/CWA-2024-006.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

**Severity**

Medium (Moderate + Likely)
Medium (Moderate + Likely)[^1]

**Affected versions:**

Expand Down Expand Up @@ -61,3 +61,5 @@ program by reporting a bug, please see <https://hackerone.com/cosmos>.
- 2024-08-19: Patch release announced though notifications list.
- 2024-08-20: Patch release announced on X: <https://x.com/CosmWasm/status/1825814580217381334>.
- 2024-08-21: Patch released.

[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md
2 changes: 1 addition & 1 deletion CWAs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -67,6 +67,6 @@
[CWA-2021-002]: ./CWA-2021-002.md
[CWA-2021-001]: ./CWA-2021-001.md

[^1]: following Amulet's Severity Classification Framework: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md

[^2]: Contracts: everything compiled into Wasm (comswasm-std, other contract libraries); VM: everything executing contracts (cosmwasm-vm, wasmvm); x/wasm: integration of the VM into the chain (wasmd)