Secured #2: Public Vulnerability Disclosures

on

|

views

and

comments



Right now, we disclosed the primary set of vulnerabilities from the Ethereum Basis’s Bug Bounty Applications. These vulnerabilities had been beforehand found and reported on to the Ethereum Basis or shopper groups through the Bug Bounty Applications for each the Execution Layer and Consensus Layer.

By way of its Bug Bounty Applications, which permit the Ethereum Basis (EF) to coordinate and cross-check vulnerabilities throughout shoppers, the EF at present accepts vulnerability experiences for Nimbus, Teku, Lighthouse, Prysm, Lodestar, Go Ethereum, Nethermind, Erigon and Besu.

New repository & vulnerability checklist

The complete checklist of vulnerabilities, together with extra data, will be discovered in a git repository right here.

The brand new disclosures repository catalogues all identified vulnerabilities that had been patched previous to the newest hardforks on the Execution Layer and Consensus Layer.

We wish to give a large shout out to everybody concerned within the discovery and reporting of vulnerabilities, in addition to to the groups accountable for fixing them. Whereas we’ve got tried to incorporate the names or aliases of the reporters, there are lots of builders and researchers inside the shopper groups and within the Ethereum Basis who discovered and corrected vulnerabilities exterior of the bounty program. There are additionally many unsung heroes corresponding to shopper group builders, group members, and plenty of extra who’ve spent numerous hours triaging, cross-checking, and mitigating vulnerabilities earlier than they may very well be exploited.

For extra data, and to study extra about disclosure insurance policies, timelines, and cataloging, head over to the brand new disclosures repository.

Your immense efforts have been instrumental to making sure Ethereum’s safety. Thanks!

Share this
Tags

Must-read

‘Lidar is lame’: why Elon Musk’s imaginative and prescient for a self-driving Tesla taxi faltered | Tesla

After years of promising traders that thousands and thousands of Tesla robotaxis would quickly fill the streets, Elon Musk debuted his driverless automobile...

Common Motors names new CEO of troubled self-driving subsidiary Cruise | GM

Common Motors on Tuesday named a veteran know-how government with roots within the online game business to steer its troubled robotaxi service Cruise...

Meet Mercy and Anita – the African employees driving the AI revolution, for simply over a greenback an hour | Synthetic intelligence (AI)

Mercy craned ahead, took a deep breath and loaded one other process on her pc. One after one other, disturbing photographs and movies...

Recent articles

More like this

LEAVE A REPLY

Please enter your comment!
Please enter your name here