CVE-2021-4300

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-4300
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-4300.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-4300
Published
2023-01-04T22:15:08.903Z
Modified
2025-11-14T12:33:34.048458Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability has been found in ghostlander Halcyon and classified as critical. Affected by this vulnerability is the function CBlock::AddToBlockIndex of the file src/main.cpp of the component Block Verification. The manipulation leads to improper access controls. The attack can be launched remotely. Upgrading to version 1.1.1.0-hal is able to address this issue. The identifier of the patch is 0675b25ae9cc10b5fdc8ea3a32c642979762d45e. It is recommended to upgrade the affected component. The identifier VDB-217417 was assigned to this vulnerability.

References

Affected packages

Git / github.com/ghostlander/halcyon

Affected ranges

Type
GIT
Repo
https://github.com/ghostlander/halcyon
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

v1.*

v1.1.0.0-hal
v1.1.0.1-hal
v1.1.0.2-hal
v1.1.0.3-hal

Database specific

vanir_signatures

[
    {
        "digest": {
            "function_hash": "10305248216024656084912338977232963110",
            "length": 2940.0
        },
        "target": {
            "function": "CBlock::CheckBlock",
            "file": "src/main.cpp"
        },
        "id": "CVE-2021-4300-c1935fa3",
        "source": "https://github.com/ghostlander/halcyon/commit/0675b25ae9cc10b5fdc8ea3a32c642979762d45e",
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1"
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "105355511900724386530181311696563767876",
                "269402346052448994325041188111138389157",
                "309460302393590256566086224470897904031",
                "230116994094110080314317628614218126604",
                "276826980275533762924066868480772846694",
                "98543386248935302488754600721159916577",
                "287758536505900560444298499842733742026",
                "311147851611641751698846828549482860550",
                "284908018889021951316895529834250969422",
                "62401294572304355820185300454867920975",
                "122535623190981126376093543514470620962",
                "104241435607975237020381975562207888764",
                "174882452581893492705787870648806259108",
                "278182712261701462478699443981443333452",
                "74795623710365316666848520038722447926",
                "95810954626867192821845781116982777205",
                "184047123222678067942587501639909895204",
                "127599239359550807544091793257356758189",
                "78523805818798612704265286547567952399",
                "80379672143717063287650162974945346929",
                "93772305838583647473965125620256691828",
                "94059201929041676340436963391723831613",
                "282274884842151607671657621220049004194",
                "58310343209319890363302639893853656158",
                "320444084641697696576935459030831457211",
                "116215755057023781153784689046981206461",
                "137352023725335996649038982297868078275",
                "283876739839686851178925081232490303776",
                "227835412256598348415626178544836038418",
                "178674064702455874137163593537777265956",
                "294594937731353267025049352776862019873",
                "120241644017525521818705461085648474671"
            ]
        },
        "target": {
            "file": "src/main.cpp"
        },
        "id": "CVE-2021-4300-c40e6802",
        "source": "https://github.com/ghostlander/halcyon/commit/0675b25ae9cc10b5fdc8ea3a32c642979762d45e",
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1"
    }
]