Hyperbridge is a hyper-scalable coprocessor for verifiable, cross-chain interoperability. A critical vulnerability was discovered in the ismp-grandpa crate, that allowed a malicious prover easily convince the verifier of the finality of arbitrary headers. This could be used to steal funds or compromise other kinds of cross-chain applications. This vulnerability is fixed in 15.0.1.
                
            Metrics
Affected Vendors & Products
References
        History
                    Tue, 28 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Tue, 28 Jan 2025 15:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Hyperbridge is a hyper-scalable coprocessor for verifiable, cross-chain interoperability. A critical vulnerability was discovered in the ismp-grandpa crate, that allowed a malicious prover easily convince the verifier of the finality of arbitrary headers. This could be used to steal funds or compromise other kinds of cross-chain applications. This vulnerability is fixed in 15.0.1. | |
| Title | Critical vulnerability in `ismp-grandpa` <v15.0.1 | |
| Weaknesses | CWE-347 CWE-670  | 
|
| References | 
         | 
        
  | 
| Metrics | 
        
        cvssV4_0
         
  | 
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-01-28T15:41:43.461Z
Updated: 2025-01-28T16:07:48.018Z
Reserved: 2025-01-23T17:11:35.838Z
Link: CVE-2025-24800
Updated: 2025-01-28T16:07:43.771Z
Status : Received
Published: 2025-01-28T16:15:45.063
Modified: 2025-01-28T16:15:45.063
Link: CVE-2025-24800
No data.