From d82277157036ed319cbbfa7a8b9b44c5cbb202ec Mon Sep 17 00:00:00 2001 From: Simon Warta Date: Wed, 21 Aug 2024 17:27:44 +0200 Subject: [PATCH 1/2] Add aliases for CWA-2024-005 and CWA-2024-006 --- CWAs/README.md | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/CWAs/README.md b/CWAs/README.md index 2fedff0..0a768d7 100644 --- a/CWAs/README.md +++ b/CWAs/README.md @@ -4,8 +4,8 @@ | Severity[^1] | Scope[^2] | ID | Aliases | | ------------ | --------- | ----------------------------------------------------------------------- | ------------------------------------------ | -| Medium | x/wasm | [CWA-2024-006: Non-deterministic module_query_safe query][CWA-2024-006] | | -| High | x/wasm | [CWA-2024-005: Stackoverflow in wasmd][CWA-2024-005] | | +| Medium | x/wasm | [CWA-2024-006: Non-deterministic module_query_safe query][CWA-2024-006] | [GHSA-fpgj-cr28-fvpx] | +| High | x/wasm | [CWA-2024-005: Stackoverflow in wasmd][CWA-2024-005] | [GHSA-g8w7-7vgg-x7xg] | | Medium | VM | [CWA-2024-004: Gas mispricing in cosmwasm-vm][CWA-2024-004] | [RUSTSEC-2024-0361], [GHSA-rg2q-2jh9-447q] | | Low | x/wasm | [CWA-2024-003: Large address count in ValidateBasic][CWA-2024-003] | [GHSA-m3rh-cvr5-x6q4] | | Medium | Contracts | [CWA-2024-002: Arithmetic overflows in cosmwasm-std][CWA-2024-002] | [RUSTSEC-2024-0338], [GHSA-8724-5xmm-w5xq] | @@ -24,6 +24,8 @@ [GHSA-rr69-rxr6-8qwf]: https://github.com/advisories/GHSA-rr69-rxr6-8qwf [GHSA-rg2q-2jh9-447q]: https://github.com/advisories/GHSA-rg2q-2jh9-447q [GHSA-m3rh-cvr5-x6q4]: https://github.com/advisories/GHSA-m3rh-cvr5-x6q4 +[GHSA-g8w7-7vgg-x7xg]: https://github.com/CosmWasm/wasmd/security/advisories/GHSA-g8w7-7vgg-x7xg +[GHSA-fpgj-cr28-fvpx]: https://github.com/CosmWasm/wasmd/security/advisories/GHSA-fpgj-cr28-fvpx ## 2023 From b4e698d23107a70e419f3f92791b861ef02b4140 Mon Sep 17 00:00:00 2001 From: Simon Warta <2603011+webmaster128@users.noreply.github.com> Date: Thu, 22 Aug 2024 09:44:29 +0200 Subject: [PATCH 2/2] Update CWAs/README.md Co-authored-by: Christoph Otter --- CWAs/README.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/CWAs/README.md b/CWAs/README.md index 0a768d7..cef57a2 100644 --- a/CWAs/README.md +++ b/CWAs/README.md @@ -24,8 +24,8 @@ [GHSA-rr69-rxr6-8qwf]: https://github.com/advisories/GHSA-rr69-rxr6-8qwf [GHSA-rg2q-2jh9-447q]: https://github.com/advisories/GHSA-rg2q-2jh9-447q [GHSA-m3rh-cvr5-x6q4]: https://github.com/advisories/GHSA-m3rh-cvr5-x6q4 -[GHSA-g8w7-7vgg-x7xg]: https://github.com/CosmWasm/wasmd/security/advisories/GHSA-g8w7-7vgg-x7xg -[GHSA-fpgj-cr28-fvpx]: https://github.com/CosmWasm/wasmd/security/advisories/GHSA-fpgj-cr28-fvpx +[GHSA-g8w7-7vgg-x7xg]: https://github.com/advisories/GHSA-g8w7-7vgg-x7xg +[GHSA-fpgj-cr28-fvpx]: https://github.com/advisories/GHSA-fpgj-cr28-fvpx ## 2023