CVE-2022-47547: Medium severity protocol Gossipsub vulnerability
GossipSub 1.1, as used for Ethereum 2.0, allows a peer to maintain a positive score (and thus not be pruned from the network) even though it continuously misbehaves by never forwarding topic messages.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-47547?
CVE-2022-47547 has been assigned a high severity rating due to its potential impact on the reliability of Ethereum 2.0's gossip protocol.
How do I fix CVE-2022-47547?
To mitigate CVE-2022-47547, ensure you are using an updated version of the Gossipsub protocol that addresses this vulnerability.
What systems are affected by CVE-2022-47547?
CVE-2022-47547 affects implementations of Gossipsub version 1.1, particularly those used within the Ethereum 2.0 framework.
What is the nature of the vulnerability in CVE-2022-47547?
CVE-2022-47547 allows misbehaving peers to persist in the network by exploiting the score management system of the Gossipsub protocol.
Who is responsible for reporting CVE-2022-47547?
CVE-2022-47547 was reported by researchers focusing on the security of distributed systems and peer-to-peer protocols.